Description
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an integer overflow or wraparound in Microsoft Office Outlook that allows an unauthorized attacker to execute arbitrary code over a network. This flaw can lead to remote code execution, giving the attacker complete control over the affected system. The weakness is a classic integer over/underflow error, classified as CWE‑190.

Affected Systems

Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Outlook 2016. No specific version ranges were provided in the vendor advisory.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, reducing immediate concern. Based on the description, it is inferred that the attack vector is network-based and requires an unauthorized attacker to obtain connectivity to the vulnerable Outlook installation, after which the integer overflow can be triggered to run attacker code.

Generated by OpenCVE AI on August 12, 2026 at 14:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all affected Microsoft Office and Outlook installations to the latest security patch as detailed in the Microsoft update guide
  • Restrict or disable legacy authentication protocols that may expose Outlook to remote attackers
  • Monitor network traffic for suspicious connections to Outlook services and audit for unusual activity

Generated by OpenCVE AI on August 12, 2026 at 14:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft outlook
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:x86:*
Vendors & Products Microsoft outlook

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Title Microsoft Outlook Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft outlook 2016
Weaknesses CWE-190
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:outlook_2016:*:*:*:*:*:x86:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft outlook 2016
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2019 Office 2021 Office 2024 Outlook Outlook 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:08:22.705Z

Reserved: 2026-08-04T00:01:20.934Z

Link: CVE-2026-70329

cve-icon Vulnrichment

Updated: 2026-08-11T19:21:24.207Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:10.777

Modified: 2026-08-14T15:33:03.130

Link: CVE-2026-70329

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T15:00:06Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound