Impact
An use‑after‑free flaw in Microsoft Office Outlook enables an attacker to execute malicious code on a target system. This vulnerability maps to CWE‑416 and poses a high severity risk because it allows code execution without authentication or local access.
Affected Systems
Affected products include Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office 365 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024, and Microsoft Word 2016 across all listed versions.
Risk and Exploitability
The CVSS score of 8.8 indicates a high impact vulnerability. Because the attack vector is described as over a network, the likely entry method is a remote payload such as a malicious email or link that triggers the use‑after‑free condition. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation may not yet be widespread.
OpenCVE Enrichment