PT-2026-99098 · Microsoft · Outlook
CVE-2026-100208
·
Published
2026-09-25
·
Updated
2026-09-26
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Office Outlook (affected versions not specified)
Description
An integer overflow or wraparound occurs in Microsoft Office Outlook, which could allow an unauthorized attacker to execute code remotely over a network. This issue requires user interaction, such as clicking a link or opening an attachment, and is characterized by high attack complexity and requires no special privileges.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, treat unexpected calendar invites and the opening of attachments as high-risk activities.
RCE
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Outlook