CVE-2026-80073: Microsoft Office Outlook Information Disclosure Vulnerability
Microsoft Office Outlook Information Disclosure Vulnerability
Other sources
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.14334.20896 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20136 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20204 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5569.1000Patch KB5002919 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.17932.20960
Event History
Frequently Asked Questions
Which Office installations should be prioritized for review?
Review Microsoft 365 Apps for Enterprise, Outlook 2016, Office 2019 32-bit and 64-bit editions, Office LTSC 2021 32-bit and 64-bit editions, and Office LTSC 2024 32-bit and 64-bit editions.
Does an attacker need prior access or elevated privileges to exploit this issue?
The vulnerability is rated network-accessible with low attack complexity and requires no privileges. User interaction is required, so exploitation depends on a user performing an interaction.