PT-2026-99098 · Microsoft · Outlook

CVE-2026-100208

·

Published

2026-09-25

·

Updated

2026-09-26

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Office Outlook (affected versions not specified)
Description An integer overflow or wraparound occurs in Microsoft Office Outlook, which could allow an unauthorized attacker to execute code remotely over a network. This issue requires user interaction, such as clicking a link or opening an attachment, and is characterized by high attack complexity and requires no special privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary mitigation, treat unexpected calendar invites and the opening of attachments as high-risk activities.

RCE

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100208

Affected Products

Outlook