📦 Outlook

by Microsoft

🔍 What is Outlook?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-23397

CRITICAL CVSS 9.8 Mar 14, 2023

CVE-2023-23397 is a critical elevation of privilege vulnerability in Microsoft Outlook that allows attackers to steal NTLM hashes without user interaction. When exploited, it enables credential theft ...

CVE-2025-29805

HIGH CVSS 7.5 Apr 8, 2025

CVE-2025-29805 is an information disclosure vulnerability in Outlook for Android that allows unauthorized attackers to access sensitive information over a network. This affects users of Outlook for An...

CVE-2025-21361

HIGH CVSS 7.8 Jan 14, 2025

Microsoft Outlook contains a remote code execution vulnerability that allows attackers to execute arbitrary code on a target system by sending a specially crafted email. This affects users running vul...

CVE-2024-42220

HIGH CVSS 7.1 Dec 18, 2024

A library injection vulnerability in Microsoft Outlook for macOS allows malicious applications to inject code and leverage Outlook's permissions, potentially bypassing security controls. This affects ...

CVE-2024-20670

HIGH CVSS 8.1 Apr 9, 2024

This vulnerability allows attackers to spoof email sender information in Outlook for Windows, making malicious emails appear to come from trusted sources. It affects users running vulnerable versions ...

CVE-2024-21378

HIGH CVSS 8.8 Feb 13, 2024

This vulnerability allows remote code execution through Microsoft Outlook when processing specially crafted email messages. Attackers could execute arbitrary code on the target system with the privile...

CVE-2023-35311

HIGH CVSS 8.8 Jul 11, 2023

This vulnerability allows attackers to bypass security features in Microsoft Outlook, potentially enabling them to execute malicious code or access restricted content. It affects users running vulnera...

CVE-2022-35742

HIGH CVSS 7.5 Jun 1, 2023

CVE-2022-35742 is a denial-of-service vulnerability in Microsoft Outlook that allows attackers to crash the application by sending specially crafted emails. This affects users running vulnerable versi...

CVE-2025-21357

MEDIUM CVSS 6.7 Jan 14, 2025

Microsoft Outlook contains a remote code execution vulnerability that allows attackers to execute arbitrary code on a victim's system by sending a specially crafted email. This affects users running v...

CVE-2024-43604

MEDIUM CVSS 5.7 Oct 8, 2024

This vulnerability in Outlook for Android allows attackers to elevate privileges within the app, potentially accessing sensitive data or performing unauthorized actions. It affects users running vulne...

CVE-2020-1493

MEDIUM CVSS 5.5 Aug 17, 2020

This CVE describes an information disclosure vulnerability in Microsoft Outlook where files attached as links to emails could be accessed by unauthorized users. Attackers could share email attachments...

CVE-2020-1483

MEDIUM CVSS 5.0 Aug 17, 2020

This is a remote code execution vulnerability in Microsoft Outlook where specially crafted files can trigger memory handling errors, allowing attackers to run arbitrary code as the current user. Users...

CVE-2019-1218

MEDIUM CVSS 5.4 Aug 14, 2019

A spoofing vulnerability in Microsoft Outlook for iOS allows authenticated attackers to send specially crafted emails that trigger cross-site scripting (XSS) attacks. When exploited, malicious scripts...