Microsoft Outlook vulnerabilities
106 known vulnerabilities affecting microsoft/outlook.
Total CVEs
106
CISA KEV
5
actively exploited
Public exploits
18
Exploited in wild
6
Severity breakdown
CRITICAL11HIGH52MEDIUM43
Vulnerabilities
Page 1 of 6
CVE-2023-23397P1CRITICALCVSS 9.8KEVPoCRansomwarev2013v20162023-03-14
CVE-2023-23397 [CRITICAL] CWE-20 CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability
Microsoft Outlook Elevation of Privilege Vulnerability
nvd
CVE-2017-11774P1HIGHCVSS 7.8KEVPoCv2010v2013+1 more2017-10-13
CVE-2017-11774 [HIGH] CWE-119 CVE-2017-11774: Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execu
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."
nvd
CVE-2015-1641P1HIGHCVSS 7.8KEVRansomwarev20112015-04-14
CVE-2015-1641 [HIGH] CWE-787 CVE-2015-1641: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for M
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka "Microsoft Offic
nvd
CVE-2007-0671P2HIGHCVSS 8.8KEVv2000v2002+1 more2007-02-03
CVE-2007-0671 [HIGH] CVE-2007-0671: Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Of
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
nvd
CVE-2023-35311P1HIGHCVSS 7.5KEVv2013v20162023-07-11
CVE-2023-35311 [HIGH] CWE-367 CVE-2023-35311: Microsoft Outlook Security Feature Bypass Vulnerability
Microsoft Outlook Security Feature Bypass Vulnerability
nvd
CVE-2006-4868P2CRITICALCVSS 9.3ExploitedPoCv20032006-09-19
CVE-2006-4868 [CRITICAL] CWE-119 CVE-2006-4868: Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.
nvd
CVE-2010-0266P2CRITICALCVSS 9.3PoCv2002v2003+1 more2010-07-15
CVE-2010-0266 [CRITICAL] CWE-94 CVE-2010-0266: Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail at
Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."
nvd
CVE-2004-0204P3HIGHCVSS 7.5PoCv20032004-08-06
CVE-2004-0204 [HIGH] CVE-2004-0204: Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10,
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynami
nvd
CVE-2004-0200P3CRITICALCVSS 9.3PoCv2002v20032004-09-28
CVE-2004-0200 [CRITICAL] CVE-2004-0200: Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
nvd
CVE-2023-33131P2HIGHCVSS 8.8PoCv2013v20162023-06-14
CVE-2023-33131 [HIGH] CWE-94 CVE-2023-33131: Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2001-0538P3CRITICALCVSS 10.0PoC≤ 20022001-08-14
CVE-2001-0538 [CRITICAL] CVE-2001-0538: Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.
nvd
CVE-2004-0121P3HIGHCVSS 7.5PoCv20022004-04-15
CVE-2004-0121 [HIGH] CWE-88 CVE-2004-0121: Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters o
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
nvd
CVE-2020-16947P2HIGHCVSS 8.8v20162020-10-16
CVE-2020-16947 [HIGH] CWE-125 CVE-2020-16947: <p>A remote code execution vulnerability exists in Microsoft Outlook software when the software fail
A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the targeted user. If the targeted user is logged on with administrative user rights, an attacker could take control
nvd
CVE-2024-21378P2HIGHCVSS 8.8v20162024-02-13
CVE-2024-21378 [HIGH] CWE-94 CVE-2024-21378: Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2003-1378P3HIGHCVSS 8.8PoCv20002003-12-31
CVE-2003-1378 [HIGH] CWE-264 CVE-2003-1378: Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows
Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
nvd
CVE-2024-30103P2HIGHCVSS 8.8v20162024-06-11
CVE-2024-30103 [HIGH] CWE-184 CVE-2024-30103: Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2025-47171P3MEDIUMCVSS 6.7PoCv20162025-06-10
CVE-2025-47171 [MEDIUM] CWE-20 CVE-2025-47171: Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
nvd
CVE-2018-0852P3HIGHCVSS 8.8v2010v2013+1 more2018-02-15
CVE-2018-0852 [HIGH] CVE-2018-0852: Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1 and RT SP1, Micro
Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1 and RT SP1, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Outlook handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0851.
nvd
CVE-2018-0851P3HIGHCVSS 8.8v2010v2013+1 more2018-02-15
CVE-2018-0851 [HIGH] CWE-787 CVE-2018-0851: Microsoft Office 2007 SP2, Microsoft Office Word Viewer, Microsoft Office 2010 SP2, Microsoft Office
Microsoft Office 2007 SP2, Microsoft Office Word Viewer, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Office handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique
nvd
CVE-2018-8582P3HIGHCVSS 8.8v2010-sp2v2013-sp1+1 more2018-11-14
CVE-2018-8582 [HIGH] CVE-2018-8582: A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modi
A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export files, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8522, CVE-2018-8524, CVE-2018-8576.
nvd
1 / 6Next →