Junglewise Threat Intelligence

CVE-2023-37524: HCL Traveler for Microsoft Outlook use of unmaintained .NET Framework 4.5

CVE-2023-37524 · Severity: high · CVSS 7.7 · Published 2026-06-27

Technologies: HCL Software Traveler for Microsoft Outlook. Vendors: HCL Software.

Executive brief

HCL Traveler for Microsoft Outlook (HTMO) is vulnerable because it relies on an obsolete version of the Microsoft .NET Framework (version 4.5) that no longer receives security updates. This software is used to integrate HCL Domino mail and calendar services with the Microsoft Outlook client. Because the underlying framework is end-of-life, attackers could potentially exploit known, unpatched security flaws in the framework to compromise the user's workstation or access sensitive email data.

Technical details

HCL Traveler for Microsoft Outlook (HTMO) versions prior to 3.0.6 utilize Microsoft .NET Framework 4.5, which has reached end-of-life (EOL) and no longer receives security patches. This falls under CWE-1104 (Use of Unmaintained Third Party Components). The vulnerability is local in nature and requires user interaction, but it carries a high impact because the underlying framework's unpatched vulnerabilities could lead to full system compromise or data exfiltration. The issue is resolved in HTMO version 3.0.6, which migrates the application to a supported version of the .NET Framework.

Affected products

  • HCL Software Traveler for Microsoft Outlook (HTMO) < 3.0.6

Timeline

  • 2026-06-27: advisory: NVD publication date

References

Related threats