← back
CVE-2025-21361highCWE-641

Microsoft Outlook Remote Code Execution Vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.8epss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in Microsoft Outlook allows an attacker to run malicious code on your computer by sending a specially crafted email. If you open that email, the attacker gains control of your system.

Technical detail

This RCE vulnerability in Microsoft Outlook exploits improper input validation (CWE-641: Incorrect Initialization with Hard-Coded Network Resource Configuration Elements) through a maliciously crafted email message. Successful exploitation requires user interaction (opening the email) and results in arbitrary code execution with the privileges of the Outlook process, potentially compromising the entire system.

Summary generated and translated by AI from the official description.
Microsoft Outlook Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RC:C