CVE-2025-21361
Published: 14 January 2025
Description
Microsoft Outlook Remote Code Execution Vulnerability
Security Summary
CVE-2025-21361 is a Remote Code Execution vulnerability affecting Microsoft Outlook. Published on 2025-01-14, it carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-641 and NVD-CWE-noinfo.
Exploitation requires local access to the target system, low attack complexity, no special privileges, and user interaction. A local attacker could leverage this to execute arbitrary code, resulting in high impacts to confidentiality, integrity, and availability on the affected system.
The Microsoft Security Response Center provides details on mitigation and patches in its update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21361.
Details
- CWE(s)