Junglewise Threat Intelligence

CVE-2026-78519: Microsoft Office Outlook use of uninitialized resource remote code execution

CVE-2026-78519 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Office Outlook is an email and calendar client used by millions of organizations worldwide. This vulnerability allows an attacker to execute malicious code on a victim's computer by sending a specially crafted email or network message, potentially leading to data theft, system compromise, or lateral movement within corporate networks.

Technical details

This vulnerability involves the use of uninitialized resource in Microsoft Office Outlook, which can be exploited through network-based attack vectors. An attacker can craft malicious input that triggers the uninitialized resource condition, leading to code execution with the privileges of the Outlook process. The vulnerability is remotely exploitable without requiring user authentication or special preconditions beyond receiving or opening a malicious message. A patch is expected to be available through Microsoft's security update process.

Affected products

  • Microsoft Office Outlook

Timeline

  • 2026-09-08: disclosed

References

Related threats