PT-2025-1238 · Microsoft · Office+1
Arnold Osipov
+6
·
Published
2025-01-14
·
Updated
2025-10-06
·
CVE-2025-21357
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook versions 2016
Microsoft Office versions 2019 through 2024
Description
The issue allows remote attackers to execute arbitrary code and affect the system. It is reported that this issue has been patched by Microsoft with the aid of external researchers.
Recommendations
For Microsoft Outlook version 2016, apply the patch provided by Microsoft.
For Microsoft Office versions 2019 through 2024, apply the patch provided by Microsoft.
As a temporary workaround, consider restricting access to potentially vulnerable components until a patch is applied.
Fix
RCE
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office
Outlook