Impact
Microsoft Outlook deserializes untrusted data without proper validation, which an unauthorized attacker can exploit to perform spoofing over a network.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, and Microsoft Word 2016. No version‑specific details are provided, so all current releases of these products are potentially vulnerable.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity, while the EPSS score of less than 1% shows that this exploit is not frequently observed and is unlikely to be actively used today. The vulnerability is not listed in the CISA KEV catalog, further suggesting a lower immediate threat. Attackers could exploit this vulnerability if they can supply malicious data to Outlook components; the likely attack vector is remote over the network, but the specific attack scenario is not detailed in the CVE.
OpenCVE Enrichment