CVE-2025-21259
published 2025-02-11CVE-2025-21259: Microsoft Outlook Spoofing Vulnerability Microsoft Outlook Spoofing Vulnerability
medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.12%
62.8th percentile
Microsoft Outlook Spoofing Vulnerability
Microsoft Outlook Spoofing Vulnerability
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_outlook_for_android | >= 1.0 < 4.2501.1 | 4.2501.1 |
| msrc | microsoft_outlook_for_android | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
cvelistv55.3MEDIUM
vendor_msrc5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Outlook Spoofing Vulnerability
vendor_msrc·2025-02-11·CVSS 5.3
CVE-2025-21259 [MEDIUM] CWE-451 Microsoft Outlook Spoofing Vulnerability
Microsoft Outlook Spoofing Vulnerability
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
An attacker's message can inherit the sender's email address from another message in the UI. The attacker cannot control which message it inherits from. This issue occurs exclusively for messages in the Junk folder, as it is the only folder where the app displays the sender's email address. The attacker cannot affect confidentiality or availability.
Outlook for Android: Outlook for Android
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Remediation: Release
CVEList
Microsoft Outlook Spoofing Vulnerability
cvelistv5·2025-02-11·CVSS 5.3
CVE-2025-21259 [MEDIUM] CWE-451 Microsoft Outlook Spoofing Vulnerability
Microsoft Outlook Spoofing Vulnerability
Microsoft Outlook Spoofing Vulnerability
No detection rules found.
No public exploits indexed.
2025-02-11
Published