Junglewise Threat Intelligence

CVE-2026-80084: Microsoft Outlook out-of-bounds read information disclosure

CVE-2026-80084 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Microsoft Outlook contains an out-of-bounds read vulnerability that allows an attacker to access sensitive information from a user's email and account data over the network. An attacker could exploit this by sending a specially crafted message to trigger the vulnerability and leak confidential data without authorization.

Technical details

This vulnerability is an out-of-bounds read in Microsoft Outlook's message parsing logic. The affected component fails to properly validate buffer boundaries when processing specially crafted messages, allowing an attacker to read memory beyond the intended buffer. The attack requires network connectivity to deliver a malicious message but does not require user authentication or interaction. A successful exploit permits an attacker to disclose sensitive information resident in Outlook's memory or accessible through the application's context.

Affected products

  • Microsoft Outlook

Timeline

  • 2026-09-08: disclosed

References

Related threats