ZeroHour

CVE-2026-69629

mass

Heap-Based Buffer Overflow in Microsoft Outlook Enables Remote Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p55
Published
()
Modified
AI analysis

CVE-2026-69629 is a heap-based buffer overflow (CWE-122) in Microsoft Office Outlook that a remote, unauthenticated attacker can trigger over a network. The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates no privileges or credentials are needed on the attacker's side, but the victim must interact with attacker-controlled content — consistent with previewing or opening a specially crafted item in Outlook. A successful exploit lets the attacker execute code in the context of the Outlook user, with high impact on confidentiality, integrity, and availability (CVSS 8.8 High). All users running an affected Outlook build are exposed; effectively that means the very large installed base of Microsoft Office/Outlook users, although the provided data does not enumerate the exact affected versions or products beyond Office Outlook. There is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a 0.8% probability of exploitation in the next 30 days (56th percentile), so no in-the-wild exploitation is currently known.

What to do: Apply Microsoft's security update for Outlook/Office addressing CVE-2026-69629 through Microsoft Update or your Microsoft 365 update channel as soon as it reaches your deployment ring, and verify the affected builds against Microsoft's advisory, since exact versions are not listed in this data. Until patched, reduce exposure by using plain-text reading mode and cautioning users against previewing or opening content from untrusted senders. With no public PoC, no KEV listing, and low EPSS, this can be handled in the normal high-priority patch cycle rather than as an emergency change.

Affected
Microsoft Office Outlook
Estimated exposure
masshundreds of millions of Outlook users (order of 10^8; effectively the entire unpatched Outlook desktop install base) — Outlook is the email client bundled with Microsoft Office/Microsoft 365, whose installed base Microsoft has reported in the hundreds of millions, so a client-side Outlook code-execution flaw plausibly touches that whole estate until…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Vendors
microsoft
Products
365 apps, office 2019, office 2021, office 2024, outlook
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.