CVE-2025-29805
published 2025-04-08CVE-2025-29805: Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.41%
69.6th percentile
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_outlook_for_android | >= 1.0 < 4.2509.0 | 4.2509.0 |
| microsoft | outlook | < 4.2509.0 | 4.2509.0 |
| msrc | microsoft_outlook_for_android | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Outlook for Android Information Disclosure Vulnerability
vendor_msrc·2025-04-08·CVSS 7.5
CVE-2025-29805 [HIGH] CWE-200 Outlook for Android Information Disclosure Vulnerability
Outlook for Android Information Disclosure Vulnerability
Description: Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited the vulnerability could read targeted email messages.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Outlook for Android: Outlook for Android
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://play.google.com/stor
GHSA
GHSA-vq2r-vj3j-964w: Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a netwo
ghsa_unreviewed·2025-04-08
CVE-2025-29805 [HIGH] CWE-200 GHSA-vq2r-vj3j-964w: Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a netwo
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.
No detection rules found.
No public exploits indexed.
2025-04-08
Published