Junglewise Threat Intelligence

CVE-2024-23581: HCL Traveler for Microsoft Outlook use of unmaintained components

CVE-2024-23581 · Severity: medium · CVSS 6.7 · Published 2026-06-26

Technologies: HCL Software Traveler for Microsoft Outlook. Vendors: HCL Software.

Executive brief

HCL Traveler for Microsoft Outlook, a tool that allows users to access HCL Domino mail and calendar data through the Outlook client, contains a security vulnerability due to the use of outdated third-party components. These components are being flagged as malicious or unrecognized by security software, which could allow an attacker with local access to compromise the integrity and confidentiality of the application's data. Organizations should update to the latest version to ensure the software remains trusted and secure.

Technical details

HCL Traveler for Microsoft Outlook (HTMO) versions prior to 3.0.9 are vulnerable to CWE-1104 (Use of Unmaintained Third Party Components). The vulnerability manifests as libraries being flagged as potentially malicious or unrecognized by security scanners, indicating a risk of application modification. An attacker with local access and low privileges could potentially exploit these unmaintained components to impact the confidentiality, integrity, and availability of the system, though the attack requires high complexity and user interaction. The issue is resolved in HTMO version 3.0.9.

Affected products

  • HCL Software Traveler for Microsoft Outlook (HTMO) < 3.0.9

Timeline

  • 2026-06-26: advisory: NVD and HCL Software published the advisory.

References

Related threats