CVE-2026-70125: Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerability is rated network-accessible with low attack complexity and requires no attacker privileges. User interaction is required for exploitation.
What could a successful attack affect?
The published metrics rate confidentiality, integrity, and availability impact as high. A successful exploit could therefore have severe effects across all three security properties.
Which environments should be considered potentially affected?
Microsoft 365 Apps for Enterprise, Microsoft Outlook, and Microsoft Office LTSC 2021 and 2024 in both 32-bit and 64-bit editions are listed. The available data does not identify affected build numbers, configuration conditions, or a method to confirm exposure.