Executive brief
Microsoft Office Outlook is an email and calendar application used by millions of professionals to manage communications and scheduling. An out-of-bounds read vulnerability allows an attacker to execute arbitrary code on a user's computer by sending a specially crafted message over the network, potentially leading to unauthorized access to sensitive business data and system compromise.
Technical details
This vulnerability is an out-of-bounds read in Microsoft Office Outlook that permits remote code execution (RCE). The flaw is triggered when processing specially crafted email messages received over the network, requiring no user authentication to the vulnerable component itself. An attacker can exploit this by sending a malicious email that, when processed by Outlook, causes memory to be read outside allocated bounds, enabling arbitrary code execution in the context of the affected user. Network reachability is the primary requirement; the vulnerability does not appear to require user interaction beyond receiving the email. Microsoft has issued a security update to address this vulnerability.
Affected products
- Microsoft Office Outlook
Timeline
- 2026-09-08: disclosed