Executive brief
Microsoft Office Outlook is an email and calendar client used by millions of organizations worldwide. This vulnerability allows an attacker to execute malicious code on a victim's computer by sending a specially crafted email or network message, potentially leading to data theft, system compromise, or lateral movement within corporate networks.
Technical details
This vulnerability involves the use of uninitialized resource in Microsoft Office Outlook, which can be exploited through network-based attack vectors. An attacker can craft malicious input that triggers the uninitialized resource condition, leading to code execution with the privileges of the Outlook process. The vulnerability is remotely exploitable without requiring user authentication or special preconditions beyond receiving or opening a malicious message. A patch is expected to be available through Microsoft's security update process.
Affected products
- Microsoft Office Outlook
Timeline
- 2026-09-08: disclosed