Impact
Insufficiently protected credentials in Microsoft Office Outlook allow an unauthorized attacker to perform spoofing over a network. The weakness arises when credentials are stored or transmitted insecurely, enabling an attacker to impersonate legitimate users and send deceptive communications that can undermine trust in the email system.
Affected Systems
Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Outlook 2016 are affected. No specific version sub‑restrictions are provided in the data.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. EPSS is not available and the vulnerability is not listed in KEV, suggesting a limited likelihood of widespread exploitation. The attack likely requires unauthorized access to credentials, which the flaw exposes over the network; once credentials are obtained, an attacker can spoof legitimate users. While no public exploits are documented, patching remains recommended to eliminate the credential protection weakness.
OpenCVE Enrichment