-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ******************************************************************** Title: Microsoft Security Update Releases Issued: July 27, 2017 ******************************************************************** Summary ======= The following CVEs have undergone a major revision increment. * CVE-2017-8571 * CVE-2017-8572 * CVE-2017-8663 CVE Revision Information: ===================== CVE-2017-8571 - Title: CVE-2017-8571 | Microsoft Office Outlook Security Feature Bypass Vulnerability - https://portal.msrc.microsoft.com/en-us/security-guidance - Reason for Revision: CVE-2017-8571 has been added to the July 2017 Security Updates. Microsoft recommends that customers running affected editions of Microsoft Office install the applicable July security updates to be fully protected from this vulnerability and to address known issues 1 through 4 in the June 2017 security updates for Microsoft Outlook. For more information see the Update FAQ section of this CVE. - Originally posted: July 27, 2017 - Updated: N/A - CVE Severity Rating: Important - Version: 1.0 CVE-2017-8572 - Title: CVE-2017-8572 | Microsoft Office Outlook Information Disclosure Vulnerability - https://portal.msrc.microsoft.com/en-us/security-guidance - Reason for Revision: CVE-2017-8572 has been added to the July 2017 Security Updates. Microsoft recommends that customers running affected editions of Microsoft Office install the applicable July security updates to be fully protected from this vulnerability and to address known issues 1 through 4 in the June 2017 security updates for Microsoft Outlook. For more information see the Update FAQ section of this CVE. - Originally posted: July 27, 2017 - Updated: N/A - CVE Severity Rating: Important - Version: 1.0 CVE-2017-8663 - Title: CVE-2017-8663 | Microsoft Office Outlook Memory Corruption Vulnerability - https://portal.msrc.microsoft.com/en-us/security-guidance - Reason for Revision: CVE-2017-8663 has been added to the July 2017 Security Updates. Microsoft recommends that customers running affected editions of Microsoft Office install the applicable July security updates to be fully protected from this vulnerability and to address known issues 1 through 4 in the June 2017 security updates for Microsoft Outlook. For more information see the Update FAQ section of this CVE. - Originally posted: July 27, 2017 - Updated: N/A - CVE Severity Rating: Important - Version: 1.0 Other Information ================= Recognize and avoid fraudulent email to Microsoft customers: ============================================================= If you receive an email message that claims to be distributing a Microsoft security update, it is a hoax that may contain malware or pointers to malicious websites. Microsoft does not distribute security updates via email. The Microsoft Security Response Center (MSRC) uses PGP to digitally sign all security notifications. However, PGP is not required for reading security notifications, reading security bulletins, or installing security updates. You can obtain the MSRC public PGP key at . ******************************************************************** THE INFORMATION PROVIDED IN THIS MICROSOFT COMMUNICATION IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT APPLY. ******************************************************************** Microsoft respects your privacy. Please read our online Privacy Statement at . If you would prefer not to receive future technical security notification alerts by email from Microsoft and its family of companies please visit the following website to unsubscribe: . These settings will not affect any newsletters youave requested or any mandatory service communications that are considered part of certain Microsoft services. For legal Information, see: . This newsletter was sent by: Microsoft Corporation 1 Microsoft Way Redmond, Washington, USA 98052 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 10.2.0 (Build 1950) - not licensed for commercial use: www.pgp.com Charset: utf-8 wsFVAwUBWXn+KPsCXwi14Wq8AQiYrw/9H3YsvW7cvsrxwD3sATpjmhgAfbvVCvcB 6rY0CIVOB3EcjVxJkiOgCsvDjzPXZB85vvtt9Au54fxTCskteQc1sXaXwdyLc10s AxHJNNKwhy5JGVfxUHUa6cTBOMLJeKvquE5+ypvR5JaHlq17szfmWvlN9axaN+T1 Q6/gmGDgV7aatq9dxygwAGcKSKHbiCcapTPL6UCUmQvwuFxrGaqPzOU73dZG+Or2 ql5oRDxNmG5efHz8f/Wm416r8nvaIWnCdWize49RPaXYWSodSfm/57zPd4HS4YG5 1+BpPm5qMDSPDZiUj/UfzYbjXJNVuvFFwzai9r9MSykJbZIZ/q00qwHNnu7UPfRX c9dGFjPl9cdbyTO0NZba9jw9q3qO0EXOmLGNOfuS5PmCLdagmXZZ8bBIr145Y4S3 2ewasCufQXWo01f4ej3NjzprTNZjWCMG2pYKSCQvsYvU+OW+ILKhQba1cPnTBcep jtpyGGEy1whdJnhV7iJCdHpZBUcOxETg+8MIPnBbWnF1juwsJfjKSIErZKueJDiZ HqeMKhkerH9iAT+l5FWzeYuhXcPfhYvatR8XVAfmq2XwSpm/f/GUEy0TaQ5tH7iP yEBO2IayI65UacwZPS+GWPY2OGkTYD4k1ZB4w7C3e0YQGYe0T2vCRq4869L3/VNt /2YO1S/L2Ns= =2dck -----END PGP SIGNATURE-----