← Back to search

CVE-2026-70125

8.8 HIGH

Published 2026-09-23 · Updated 2026-09-25

AI risk analysis

Summary
This vulnerability allows remote code execution through a specially crafted email in Microsoft Office Outlook, posing a significant risk to users who open malicious emails.
Exploitability
Exploitation requires opening a malicious email, making it moderately easy for attackers to exploit, especially if users are tricked into opening the email.
Blast radius
If exploited, the attacker could execute arbitrary code on the victim's machine, leading to full control over the affected system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of Microsoft Office Outlook or apply the available patch immediately.
rceemailpatchpatch-available

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Microsoft Office Outlook Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.