Outlook 2016
by Microsoft
CVEs (19)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-30103 | Hig | 0.58 | 8.8 | 0.15 | Jun 11, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2017-8571 | Hig | 0.52 | 7.8 | 0.14 | Aug 1, 2017 | Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a security feature bypass vulnerability due to the way that it handles input, aka "Microsoft Office Outlook Security Feature Bypass… | ||
| CVE-2017-11776 | Hig | 0.50 | 7.5 | 0.19 | Oct 13, 2017 | Microsoft Outlook 2016 allows an attacker to obtain the email content of a user, due to how Outlook 2016 discloses user email content, aka "Microsoft Outlook Information Disclosure Vulnerability." | ||
| CVE-2023-33151 | Med | 0.42 | 6.5 | 0.01 | Jul 11, 2023 | Microsoft Outlook Spoofing Vulnerability | ||
| CVE-2017-0204 | Med | 0.37 | 5.5 | 0.12 | Apr 12, 2017 | Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability." | ||
| CVE-2023-23397 | 0.19 | — | 0.93 | KEV | Mar 14, 2023 | Microsoft Outlook Elevation of Privilege Vulnerability | ||
| CVE-2023-35311 | 0.12 | — | 0.00 | KEV | Jul 11, 2023 | Microsoft Outlook Security Feature Bypass Vulnerability | ||
| CVE-2025-47171 | 0.03 | — | 0.03 | Jun 10, 2025 | Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. | |||
| CVE-2023-33131 | 0.03 | — | 0.03 | Jun 13, 2023 | Microsoft Outlook Remote Code Execution Vulnerability | |||
| CVE-2024-21378 | 0.02 | — | 0.27 | Feb 13, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | |||
| CVE-2022-35742 | 0.01 | — | 0.07 | Jun 1, 2023 | Microsoft Outlook Denial of Service Vulnerability | |||
| CVE-2020-17119 | 0.01 | — | 0.18 | Dec 9, 2020 | Microsoft Outlook Information Disclosure Vulnerability | |||
| CVE-2026-21260 | 0.00 | — | 0.00 | Feb 10, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | |||
| CVE-2025-49699 | 0.00 | — | 0.00 | Jul 8, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |||
| CVE-2025-21357 | 0.00 | — | 0.00 | Jan 14, 2025 | Microsoft Outlook Remote Code Execution Vulnerability | |||
| CVE-2024-38173 | 0.00 | — | 0.00 | Aug 13, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | |||
| CVE-2024-38020 | 0.00 | — | 0.00 | Jul 9, 2024 | Microsoft Outlook Spoofing Vulnerability | |||
| CVE-2023-36763 | 0.00 | — | 0.01 | Sep 12, 2023 | Microsoft Outlook Information Disclosure Vulnerability | |||
| CVE-2023-36893 | 0.00 | — | 0.01 | Aug 8, 2023 | Microsoft Outlook Spoofing Vulnerability |
- risk 0.58cvss 8.8epss 0.15
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.52cvss 7.8epss 0.14
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a security feature bypass vulnerability due to the way that it handles input, aka "Microsoft Office Outlook Security Feature Bypass…
- risk 0.50cvss 7.5epss 0.19
Microsoft Outlook 2016 allows an attacker to obtain the email content of a user, due to how Outlook 2016 discloses user email content, aka "Microsoft Outlook Information Disclosure Vulnerability."
- risk 0.42cvss 6.5epss 0.01
Microsoft Outlook Spoofing Vulnerability
- risk 0.37cvss 5.5epss 0.12
Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
- risk 0.19cvss —epss 0.93
Microsoft Outlook Elevation of Privilege Vulnerability
- risk 0.12cvss —epss 0.00
Microsoft Outlook Security Feature Bypass Vulnerability
- CVE-2025-47171Jun 10, 2025risk 0.03cvss —epss 0.03
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
- CVE-2023-33131Jun 13, 2023risk 0.03cvss —epss 0.03
Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2024-21378Feb 13, 2024risk 0.02cvss —epss 0.27
Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2022-35742Jun 1, 2023risk 0.01cvss —epss 0.07
Microsoft Outlook Denial of Service Vulnerability
- CVE-2020-17119Dec 9, 2020risk 0.01cvss —epss 0.18
Microsoft Outlook Information Disclosure Vulnerability
- CVE-2026-21260Feb 10, 2026risk 0.00cvss —epss 0.00
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-49699Jul 8, 2025risk 0.00cvss —epss 0.00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-21357Jan 14, 2025risk 0.00cvss —epss 0.00
Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2024-38173Aug 13, 2024risk 0.00cvss —epss 0.00
Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2024-38020Jul 9, 2024risk 0.00cvss —epss 0.00
Microsoft Outlook Spoofing Vulnerability
- CVE-2023-36763Sep 12, 2023risk 0.00cvss —epss 0.01
Microsoft Outlook Information Disclosure Vulnerability
- CVE-2023-36893Aug 8, 2023risk 0.00cvss —epss 0.01
Microsoft Outlook Spoofing Vulnerability