Microsoft Outlook Has a 'Severe' Vulnerability That Could Easily Spread Malware
Microsoft has officially warned users about the existence of a vulnerability that could allow hackers to easily spread malware through the Outlook email application. The company has also released a patch for this user-after-free vulnerability (currently tracked as CVE-2025-21298), and urged users to apply it immediately.
The vulnerability, CVE-2025-21298, is rated as critical (9.8) and can cause the use of freed memory to corrupt valid data or remotely deliver malware. The flaw resides in the Object Linking and Embedding (OLED) feature of Windows, which allows users to embed and link to other documents and objects, such as adding Excel charts to Word documents. The vulnerability is also particularly dangerous because it allows users to be infected with malware when previewing specially crafted emails.
" Exploitation of the vulnerability could occur if a victim opens a specially crafted email using an affected version of Microsoft Outlook software, or if the victim's Outlook application displays a preview of a specially crafted email. This could result in an attacker executing remote code on the victim's machine," Microsoft said in a security alert .
If you can't apply the patch at this time, Microsoft recommends that you take steps like viewing your email on large LANs as plain text, and disabling or restricting NTLM traffic altogether.
What happens when you view your email in plain text? Basically, all the animations, images, and fonts are removed. Your email won't look as fancy in plain text, but it's necessary to avoid interruptions while you wait for the update to the new version of Outlook.
You should read it
- Error cannot open Outlook, this is a fix
- How to fix Outlook There is no associated program email on Windows 10
- Serious vulnerability in Microsoft Word is being used by hackers to install malware on computers
- How to fix 'Cannot Start Microsoft Outlook' error on Windows
- Fix Microsoft Outlook error 0x80040115 on Windows 10
- Microsoft confirms update KB5008212 breaks Outlook's search feature
- Microsoft Outlook RCE Vulnerability Can Sell For $400,000
- All problems with PST, Profile, Add-in ... errors on Outlook and how to fix them
May be interested
- Microsoft's source code signature control system is easily bypassed by Zloader malwareafter bypassing microsoft's protection system, the zloader malware deployed and stole the personal information of thousands of victims from 111 countries.
- Microsoft is about to roll out the new Outlook client to more users, what's remarkable?it's been almost 10 months since microsoft first announced a new version of the one outlook app with a host of feature and interface improvements.
- Some tips for Outlook 2013outlook 2013 is no stranger to many users. but how to use outlook 2013 effectively, not everyone knows. with the outlook 2013 tips below, make sure you will master this application more easily.
- Steps to create a new folder in Microsoft Outlookwhen creating a new folder in microsoft outlook, users can move and store outlook emails to another folder easily, serving the requirement of clearly separating emails in outlook.
- The spread of malware and how to prevent ityou often don't understand why viruses can infect your computer even though you have installed antivirus. so which routes have they spread and how to prevent them?
- Leaked series of screenshots of Microsoft's new 'One Outlook' email client for Windows 11microsoft is said to be working towards unifying outlook across platforms as part of the one outlook strategy the company has talked about a lot over the past few years.
- Instructions for sending free SMS via Outlookon microsoft outlook 2007, you can easily send (or receive) sms messages on your computer to any phone, just compose a new sms (the same way you compose an email on outlook), then then click send to finish.
- 10 good tips to help you work more efficiently on Outlookwith the tips below you can easily manage your mailbox effectively while avoiding the hassle of composing, sending and receiving emails in outlook.
- How to use Microsoft Outlook for project managementwhy use another software with a strange interface, when you can specify tasks, set reminders and due dates for your task list in microsoft outlook?
- A new kind of malware is spreading through Messenger and Skype spam messagesrecently, network security experts at avast security have warned of a new malware that attacks computers in two steps and spreads through messaging services like facebook messenger and skype.