Junglewise Threat Intelligence

CVE-2026-21770: HCL Traveler for Microsoft Outlook DLL hijacking

CVE-2026-21770 · Severity: medium · CVSS 6.5 · Published 2026-07-17

Technologies: HCL Software Traveler for Microsoft Outlook. Vendors: HCL Software.

Executive brief

HCL Traveler for Microsoft Outlook (HTMO), a tool that allows users to access HCL Domino mail and calendar data within the Outlook client, is vulnerable to a security flaw. An attacker with high-level access to a user's computer could replace legitimate application files with malicious ones. If successful, this could allow the attacker to take full control of the application, potentially leading to the theft of sensitive email data or further compromise of the local system.

Technical details

HCL Traveler for Microsoft Outlook (HTMO) is vulnerable to DLL hijacking (CWE-427: Uncontrolled Search Path Element). The application fails to properly validate or restrict the search path used to load dynamic link libraries (DLLs), allowing an attacker to place a malicious DLL in a location where it will be loaded by the application. Exploitation requires local access and high privileges (PR:H) on the target machine, as well as user interaction (UI:R). Successful exploitation allows for arbitrary code execution with the privileges of the HTMO process, potentially compromising confidentiality, integrity, and availability. The vulnerability is addressed in HTMO version 3.0.16.

Affected products

  • HCL Software Traveler for Microsoft Outlook (HTMO) < 3.0.16

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory

References

Related threats