Jan 2025: Microsoft Outlook Remote Code Execution Vulnerability
CVE-2025-21357 Published on January 14, 2025

Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability

Vendor Advisory NVD

Weakness Type

Use of Uninitialized Resource

The software uses or accesses a resource that has not been initialized. When a resource has not been properly initialized, the software may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the software.


Products Associated with CVE-2025-21357

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2025-21357 are published in these products:

 
 
 
 
 
 
 
 

Affected Versions

Microsoft 365 Apps for Enterprise: Microsoft Office 2019: Microsoft Office LTSC 2021: Microsoft Office LTSC 2024: Microsoft Outlook 2016:

Exploit Probability

EPSS
0.32%
Percentile
54.95%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.