Executive brief
HCL Traveler for Microsoft Outlook (HTMO) is vulnerable because it relies on an obsolete version of the Microsoft .NET Framework (version 4.5) that no longer receives security updates. This software is used to integrate HCL Domino mail and calendar services with the Microsoft Outlook client. Because the underlying framework is end-of-life, attackers could potentially exploit known, unpatched security flaws in the framework to compromise the user's workstation or access sensitive email data.
Technical details
HCL Traveler for Microsoft Outlook (HTMO) versions prior to 3.0.6 utilize Microsoft .NET Framework 4.5, which has reached end-of-life (EOL) and no longer receives security patches. This falls under CWE-1104 (Use of Unmaintained Third Party Components). The vulnerability is local in nature and requires user interaction, but it carries a high impact because the underlying framework's unpatched vulnerabilities could lead to full system compromise or data exfiltration. The issue is resolved in HTMO version 3.0.6, which migrates the application to a supported version of the .NET Framework.
Affected products
- HCL Software Traveler for Microsoft Outlook (HTMO) < 3.0.6
Timeline
- 2026-06-27: advisory: NVD publication date