Impact
The vulnerability is an integer overflow or wraparound in Microsoft Office Outlook that allows an unauthorized attacker to execute arbitrary code over a network. This flaw can lead to remote code execution, giving the attacker complete control over the affected system. The weakness is a classic integer over/underflow error, classified as CWE‑190.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Outlook 2016. No specific version ranges were provided in the vendor advisory.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, reducing immediate concern. Based on the description, it is inferred that the attack vector is network-based and requires an unauthorized attacker to obtain connectivity to the vulnerable Outlook installation, after which the integer overflow can be triggered to run attacker code.
OpenCVE Enrichment