CVE-2025-21361: high-severity vulnerability in Microsoft Office LTSC for Mac 2021
Microsoft Outlook Remote Code Execution Vulnerability
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A flaw in Microsoft Outlook allows an attacker to run malicious code on your computer by sending a specially crafted email. If you open that email, the attacker gains control of your system.
This RCE vulnerability in Microsoft Outlook exploits improper input validation (CWE-641: Incorrect Initialization with Hard-Coded Network Resource Configuration Elements) through a maliciously crafted email message. Successful exploitation requires user interaction (opening the email) and results in arbitrary code execution with the privileges of the Outlook process, potentially compromising the entire system.
In the same product, most dangerous first.