Outlook
by Microsoft
CVEs (151)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-29805 | Hig | 0.49 | 7.5 | 0.01 | Apr 8, 2025 | Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2024-26204 | Hig | 0.49 | 7.5 | 0.02 | Mar 12, 2024 | Outlook for Android Information Disclosure Vulnerability | ||
| CVE-2023-36763 | Hig | 0.49 | 7.5 | 0.02 | Sep 12, 2023 | Microsoft Outlook Information Disclosure Vulnerability | ||
| CVE-2018-8310 | Hig | 0.49 | 7.5 | 0.05 | Jul 11, 2018 | A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office. | ||
| CVE-2026-42893 | Hig | 0.48 | 7.4 | 0.00 | May 12, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network. | ||
| CVE-2021-31949 | Hig | 0.48 | 7.3 | 0.03 | Jun 8, 2021 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2025-47171 | Med | 0.47 | 6.7 | 0.02 | Jun 10, 2025 | Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. | ||
| CVE-2026-26133 | Hig | 0.46 | 7.1 | 0.00 | Mar 16, 2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-49699 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2024-42220 | Hig | 0.46 | 7.1 | 0.01 | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this… | ||
| CVE-2024-21402 | Hig | 0.46 | 7.1 | 0.00 | Feb 13, 2024 | Microsoft Outlook Elevation of Privilege Vulnerability | ||
| CVE-2021-28452 | Hig | 0.46 | 7.1 | 0.01 | Apr 13, 2021 | Microsoft Outlook Memory Corruption Vulnerability | ||
| CVE-2025-21357 | Med | 0.44 | 6.7 | 0.01 | Jan 14, 2025 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2024-38173 | Med | 0.44 | 6.7 | 0.01 | Aug 13, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2023-35636 | Med | 0.44 | 6.5 | 0.18 | Dec 12, 2023 | Microsoft Outlook Information Disclosure Vulnerability | ||
| CVE-2023-33153 | Med | 0.44 | 6.8 | 0.01 | Jul 11, 2023 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2016-3366 | Med | 0.44 | 6.5 | 0.16 | Sep 14, 2016 | Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016, and Outlook 2016 for Mac do not properly implement RFC 2046, which allows remote attackers to bypass virus or spam detection via crafted MIME data in an e-mail attachment, aka… | ||
| CVE-2023-33151 | Med | 0.43 | 6.5 | 0.03 | Jul 11, 2023 | Microsoft Outlook Spoofing Vulnerability | ||
| CVE-2020-17119 | Med | 0.43 | 6.5 | 0.04 | Dec 10, 2020 | Microsoft Outlook Information Disclosure Vulnerability | ||
| CVE-2020-0696 | Med | 0.43 | 6.5 | 0.05 | Feb 11, 2020 | A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly handles the parsing of URI formats, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'. |
- risk 0.49cvss 7.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.02
Outlook for Android Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Outlook Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.05
A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office.
- risk 0.48cvss 7.4epss 0.00
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.
- risk 0.48cvss 7.3epss 0.03
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.47cvss 6.7epss 0.02
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
- risk 0.46cvss 7.1epss 0.00
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.46cvss 7.0epss 0.00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.46cvss 7.1epss 0.01
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this…
- risk 0.46cvss 7.1epss 0.00
Microsoft Outlook Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft Outlook Memory Corruption Vulnerability
- risk 0.44cvss 6.7epss 0.01
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.44cvss 6.7epss 0.01
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.44cvss 6.5epss 0.18
Microsoft Outlook Information Disclosure Vulnerability
- risk 0.44cvss 6.8epss 0.01
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.44cvss 6.5epss 0.16
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016, and Outlook 2016 for Mac do not properly implement RFC 2046, which allows remote attackers to bypass virus or spam detection via crafted MIME data in an e-mail attachment, aka…
- risk 0.43cvss 6.5epss 0.03
Microsoft Outlook Spoofing Vulnerability
- risk 0.43cvss 6.5epss 0.04
Microsoft Outlook Information Disclosure Vulnerability
- risk 0.43cvss 6.5epss 0.05
A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly handles the parsing of URI formats, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
Page 3 of 8