Junglewise Threat Intelligence

CVE-2026-78525: Microsoft Office Outlook use-after-free remote code execution

CVE-2026-78525 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Outlook is an email and calendar client used across enterprise and consumer environments. A use-after-free memory vulnerability in Outlook allows an attacker to execute arbitrary code on a user's machine remotely, potentially compromising sensitive email data, calendar information, and gaining a foothold into the network.

Technical details

A use-after-free vulnerability exists in Microsoft Office Outlook where freed memory is accessed or reused improperly, leading to memory corruption and arbitrary code execution. The vulnerability can be triggered over a network without requiring authentication or special privileges. An attacker can craft a malicious email or calendar item that exploits this flaw when processed by Outlook. Successful exploitation results in remote code execution in the context of the user running Outlook. Microsoft has released patches to address this vulnerability.

Affected products

  • Microsoft Office Outlook

Timeline

  • 2026-09-08: disclosed

References

Related threats