← back
CVE-2025-21361

Microsoft Outlook Remote Code Execution Vulnerability

CVSS 7.8 HIGHEPSS 0.7%CWE-641
In short

A flaw in Microsoft Outlook allows an attacker to run malicious code on your computer by sending a specially crafted email. If you open that email, the attacker gains control of your system.

Technical detail

This RCE vulnerability in Microsoft Outlook exploits improper input validation (CWE-641: Incorrect Initialization with Hard-Coded Network Resource Configuration Elements) through a maliciously crafted email message. Successful exploitation requires user interaction (opening the email) and results in arbitrary code execution with the privileges of the Outlook process, potentially compromising the entire system.

Summary generated and translated by AI from the official description.
Microsoft Outlook Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →