Description
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

An out‑of‑bounds read occurs in Microsoft Office Outlook that lets an attacker read memory locations beyond the intended buffer. The read can expose sensitive data, leading to a breach of confidentiality for any information that the Outlook process handles. This is a classic buffer under‑read flaw described by CWE‑125.

Affected Systems

The vulnerability affects Microsoft products that include Outlook 2016, Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021, and Office LTSC 2024. No specific version numbers are listed, but all mentioned products are impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack likely requires a remote attacker to interact with the Outlook service over the network; this inference comes from the description stating “disclose information over a network.” If the service is exposed, an exploitation attempt could succeed without additional access privileges, making the risk significant for exposed systems.

Generated by OpenCVE AI on September 9, 2026 at 02:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Microsoft Office security update for Outlook from the Microsoft Security Response Center.
  • Ensure automatic updates are enabled so that future patches are applied automatically.
  • If an update cannot be applied immediately, restrict the exposed Outlook service by placing the system in a restricted network segment or configuring firewall rules to block inbound traffic to the Outlook ports.

Generated by OpenCVE AI on September 9, 2026 at 02:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Office Ltsc 2021
Microsoft microsoft Office Ltsc 2024
Vendors & Products Microsoft microsoft Office Ltsc 2021
Microsoft microsoft Office Ltsc 2024

Wed, 09 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft outlook
CPEs cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:*:x86:*
Vendors & Products Microsoft outlook

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
Title Microsoft Office Outlook Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft outlook 2016
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:outlook_2016:*:*:*:*:*:x86:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft outlook 2016
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft Office Ltsc 2021 Microsoft Office Ltsc 2024 Office 2019 Office 2021 Office 2024 Outlook Outlook 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:24.783Z

Reserved: 2026-08-25T18:37:59.827Z

Link: CVE-2026-80073

cve-icon Vulnrichment

Updated: 2026-09-08T20:01:47.300Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:49.190

Modified: 2026-09-09T18:55:32.983

Link: CVE-2026-80073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:30:10Z

Weaknesses