Microsoft Outlook
cpe:2.3:a:microsoft:outlook:*:*:*:*:*:*:*, +1 more
A remote code execution vulnerability has been identified in multiple editions of Microsoft Outlook, including Outlook 2016, Office LTSC 2024, Office LTSC 2021, Microsoft 365 Apps for Enterprise, and Office 2019. This vulnerability allows an attacker to execute arbitrary code on the affected system. The issue arises from the use of uninitialized resources, and exploitation requires the victim to open a malicious file. While the vulnerability is classified as remote code execution, it is important to note that the attack must be carried out locally, with the attacker needing access to the victim's Outlook account.
Exploitation of this vulnerability allows for remote code execution on the affected system.
Users can apply the security update provided by Microsoft to address this vulnerability. Instructions for downloading the update are available on the Microsoft Update Catalog and through the Microsoft 365 Apps Security Updates page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.