Microsoft Outlook vulnerabilities
106 known vulnerabilities affecting microsoft/outlook.
Total CVEs
106
CISA KEV
5
actively exploited
Public exploits
18
Exploited in wild
6
Severity breakdown
CRITICAL11HIGH52MEDIUM43
Vulnerabilities
Page 3 of 6
CVE-2018-8524P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-11-14
CVE-2018-8524 [HIGH] CVE-2018-8524: A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8522, CVE-2018-8576, CVE-2018-8582.
nvd
CVE-2026-42893P3HIGHCVSS 7.5fixed in 5.2617.12026-05-12
CVE-2026-42893 [HIGH] CWE-77 CVE-2026-42893: Improper neutralization of special elements used in a command ('command injection') in M365 Copilot
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.
nvd
CVE-2008-3068P3HIGHCVSS 7.5v2003v20072008-07-07
CVE-2008-3068 [HIGH] CVE-2008-3068: Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan
nvd
CVE-2004-0501P4MEDIUMCVSS 5.0PoCv20032004-08-18
CVE-2004-0501 [MEDIUM] CVE-2004-0501: Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to req
Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote attackers to know when a message has been read, verify valid e-mail addresses, and
nvd
CVE-2026-21260P3HIGHCVSS 7.5v20162026-02-10
CVE-2026-21260 [HIGH] CWE-200 CVE-2026-21260: Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an una
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2004-0526P4MEDIUMCVSS 5.0PoCv97v98+3 more2004-08-06
CVE-2004-0526 [MEDIUM] CVE-2004-0526: Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL i
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
nvd
CVE-2006-3877P3CRITICALCVSS 9.3v2000v2002+1 more2006-10-10
CVE-2006-3877 [CRITICAL] CVE-2006-3877: Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
nvd
CVE-2017-11776P3HIGHCVSS 7.5v20162017-10-13
CVE-2017-11776 [HIGH] CWE-200 CVE-2017-11776: Microsoft Outlook 2016 allows an attacker to obtain the email content of a user, due to how Outlook
Microsoft Outlook 2016 allows an attacker to obtain the email content of a user, due to how Outlook 2016 discloses user email content, aka "Microsoft Outlook Information Disclosure Vulnerability."
nvd
CVE-2021-31949P3HIGHCVSS 7.8v2013v20162021-06-08
CVE-2021-31949 [HIGH] CWE-94 CVE-2021-31949: Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2016-3366P3MEDIUMCVSS 6.5v2007v2010+2 more2016-09-14
CVE-2016-3366 [MEDIUM] CWE-284 CVE-2016-3366: Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016, a
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016, and Outlook 2016 for Mac do not properly implement RFC 2046, which allows remote attackers to bypass virus or spam detection via crafted MIME data in an e-mail attachment, aka "Microsoft Office Spoofing Vulnerability."
nvd
CVE-2025-21361P3HIGHCVSS 7.8fixed in 16.932025-01-14
CVE-2025-21361 [HIGH] CWE-641 CVE-2025-21361: Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2025-29805P3HIGHCVSS 7.5fixed in 4.2509.02025-04-08
CVE-2025-29805 [HIGH] CWE-200 CVE-2025-29805: Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthor
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-26133P3HIGHCVSS 7.1fixed in 5.2605.02026-03-16
CVE-2026-26133 [HIGH] CWE-77 CVE-2026-26133: AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2019-1200P3HIGHCVSS 7.8v2010v2013+1 more2019-08-14
CVE-2019-1200 [HIGH] CVE-2019-1200: A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user wi
nvd
CVE-2020-17119P3HIGHCVSS 7.5v2010v2013+1 more2020-12-10
CVE-2020-17119 [HIGH] CVE-2020-17119: Microsoft Outlook Information Disclosure Vulnerability
Microsoft Outlook Information Disclosure Vulnerability
nvd
CVE-2021-31941P3HIGHCVSS 7.8v20132021-06-08
CVE-2021-31941 [HIGH] CVE-2021-31941: Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2024-43604P3HIGHCVSS 8.0v20162024-10-08
CVE-2024-43604 [HIGH] CWE-1220 CVE-2024-43604: Outlook for Android Elevation of Privilege Vulnerability
Outlook for Android Elevation of Privilege Vulnerability
nvd
CVE-2000-0329P4MEDIUMCVSS 5.1PoCv98v20001999-11-11
CVE-2000-0329 [MEDIUM] CVE-2000-0329: A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an atta
A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.
nvd
CVE-2023-36763P3HIGHCVSS 7.5v20162023-09-12
CVE-2023-36763 [HIGH] CWE-200 CVE-2023-36763: Microsoft Outlook Information Disclosure Vulnerability
Microsoft Outlook Information Disclosure Vulnerability
nvd
CVE-2002-1056P3HIGHCVSS 7.5v2000v20022002-05-16
CVE-2002-1056 [HIGH] CVE-2002-1056: Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not
Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
nvd