PT-2026-40196 · Microsoft · Outlook+1
CVE-2026-40361
·
Published
2026-05-12
·
Updated
2026-06-03
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Office 2019 (affected versions not specified)
Microsoft Office 2021 (affected versions not specified)
Microsoft 365 Apps (affected versions not specified)
Microsoft Outlook (affected versions not specified)
Microsoft Word (affected versions not specified)
Description
A use-after-free issue exists in the email rendering engine, specifically within the
wwlib.dll shared library used by both Microsoft Outlook and Microsoft Word. This flaw allows an unauthorized attacker to execute arbitrary code. In Outlook, this is a zero-click attack vector, meaning it can be triggered automatically when a victim reads or previews an email in the Preview Pane, requiring no interaction such as clicking links or attachments. The issue occurs when the software re-uses a memory pointer after it has been freed, leading to heap corruption. Because Outlook (Classic) lacks an application sandbox, this allows for local code execution with the privileges of the current user, potentially compromising high-profile targets by bypassing enterprise firewalls directly via the inbox.Recommendations
Upgrade Microsoft Office 2019, 2021, and Microsoft 365 Apps to the May 12, 2026 versions.
As a temporary mitigation, configure Outlook to read all standard mail in plain text by navigating to File → Options → Trust Center → Trust Center Settings → Email Security and enabling Read all standard mail in plain text.
Fix
RCE
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Word
Outlook