PT-2025-21007 · Microsoft · Outlook

Haifei Li

·

Published

2025-05-13

·

Updated

2025-10-14

·

CVE-2025-32705

CVSS v3.1
7.8
VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Office Outlook (affected versions not specified)
Description The issue is an out-of-bounds read in Microsoft Office Outlook, which could allow an unauthorized attacker to execute code locally. The issue can be triggered by oversized files in attachments, such as ICS calendars, leading to memory corruption. As of July 2025, updates are available to address this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2025-05590
CVE-2025-32705

Affected Products

Outlook