Impact
An out‑of‑bounds read occurs in Microsoft Office Outlook that lets an attacker read memory locations beyond the intended buffer. The read can expose sensitive data, leading to a breach of confidentiality for any information that the Outlook process handles. This is a classic buffer under‑read flaw described by CWE‑125.
Affected Systems
The vulnerability affects Microsoft products that include Outlook 2016, Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021, and Office LTSC 2024. No specific version numbers are listed, but all mentioned products are impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack likely requires a remote attacker to interact with the Outlook service over the network; this inference comes from the description stating “disclose information over a network.” If the service is exposed, an exploitation attempt could succeed without additional access privileges, making the risk significant for exposed systems.
OpenCVE Enrichment