Impact
The vulnerability arises from use of an uninitialized resource within Microsoft Office Outlook, permitting an unauthorized attacker to execute arbitrary code. The weakness is classified as CWE-908, indicating a failure to correctly initialize a resource before use.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, and Microsoft Outlook 2016. Version details are not explicitly listed, so any installations of these products are potentially impacted.
Risk and Exploitability
The CVSS score of 8.8 places this flaw in the High severity range. EPSS is not available, but the absence of a KEV listing suggests that widespread exploitation has not yet been observed or catalogued. The description indicates that an unauthorized attacker can execute code over a network, implying the attack vector is network-based. No further details are reported about prerequisites or specific conditions.
OpenCVE Enrichment