PT-2026-40196 · Microsoft · Outlook+1

CVE-2026-40361

·

Published

2026-05-12

·

Updated

2026-06-03

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Office 2019 (affected versions not specified) Microsoft Office 2021 (affected versions not specified) Microsoft 365 Apps (affected versions not specified) Microsoft Outlook (affected versions not specified) Microsoft Word (affected versions not specified)
Description A use-after-free issue exists in the email rendering engine, specifically within the wwlib.dll shared library used by both Microsoft Outlook and Microsoft Word. This flaw allows an unauthorized attacker to execute arbitrary code. In Outlook, this is a zero-click attack vector, meaning it can be triggered automatically when a victim reads or previews an email in the Preview Pane, requiring no interaction such as clicking links or attachments. The issue occurs when the software re-uses a memory pointer after it has been freed, leading to heap corruption. Because Outlook (Classic) lacks an application sandbox, this allows for local code execution with the privileges of the current user, potentially compromising high-profile targets by bypassing enterprise firewalls directly via the inbox.
Recommendations Upgrade Microsoft Office 2019, 2021, and Microsoft 365 Apps to the May 12, 2026 versions. As a temporary mitigation, configure Outlook to read all standard mail in plain text by navigating to File → Options → Trust Center → Trust Center Settings → Email Security and enabling Read all standard mail in plain text.

Fix

RCE

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06819
CVE-2026-40361

Affected Products

Office Word
Outlook