Microsoft
Microsoft Outlook: vulnerabilidades y CVE
Microsoft Outlook tiene 126 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 2 son críticas y 5 figuran en el catálogo de explotación activa de CISA.
CVE126
Últimos 12 meses9
Críticas2
Explotadas activamente5
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2007-0671 | Alta (8.8) | 43% | ⚠ Explotación activa | 3 feb 2007 | Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as… |
| CVE-2023-35311 | Alta (7.5) | 16% | ⚠ Explotación activa | 11 jul 2023 | Microsoft Outlook Security Feature Bypass Vulnerability |
| CVE-2023-23397 | Crítica (9.8) | 97% | ⚠ Explotación activa | 14 mar 2023 | Microsoft Outlook Elevation of Privilege Vulnerability |
| CVE-2015-1641 | Alta (7.8) | 97% | ⚠ Explotación activa | 14 abr 2015 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office… |
| CVE-2017-11774 | Alta (7.8) | 60% | ⚠ Explotación activa | 13 oct 2017 | Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-70125 | Alta (8.8) | 0.44% | — | 23 sept 2026 | Microsoft Office Outlook Remote Code Execution Vulnerability |
| CVE-2026-80073 | Media (6.5) | 0.92% | — | 8 sept 2026 | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-78519 | Alta (8.8) | 0.82% | — | 8 sept 2026 | Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69629 | Alta (8.8) | 0.82% | — | 8 sept 2026 | Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
| CVE-2026-70329 | Alta (8.8) | 0.82% | — | 11 ago 2026 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
| CVE-2026-62882 | Media (4.3) | 0.67% | — | 11 ago 2026 | Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-42893 | Alta (7.5) | 0.71% | — | 12 may 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network. |
| CVE-2026-26133 | Alta (7.1) | 0.54% | — | 16 mar 2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-21260 | Alta (7.5) | 1.5% | — | 10 feb 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-49699 | Alta (7) | 0.35% | — | 8 jul 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-47171 | Media (6.7) | 1.7% | — | 10 jun 2025 | Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. |
| CVE-2025-29805 | Alta (7.5) | 1.5% | — | 8 abr 2025 | Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-21259 | Media (5.3) | 1.2% | — | 11 feb 2025 | Microsoft Outlook Spoofing Vulnerability |
| CVE-2025-21361 | Alta (7.8) | 0.75% | — | 14 ene 2025 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2025-21357 | Media (6.7) | 0.57% | — | 14 ene 2025 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2024-42220 | Crítica (9.1) | 0.74% | — | 18 dic 2024 | A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject… |
| CVE-2024-43604 | Alta (8) | 1.2% | — | 8 oct 2024 | Outlook for Android Elevation of Privilege Vulnerability |
| CVE-2024-43482 | Media (6.5) | 1.1% | — | 10 sept 2024 | Microsoft Outlook for iOS Information Disclosure Vulnerability |
| CVE-2024-38173 | Media (6.7) | 0.66% | — | 13 ago 2024 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2024-38020 | Media (6.5) | 1.8% | — | 9 jul 2024 | Microsoft Outlook Spoofing Vulnerability |
| CVE-2024-30103 | Alta (8.8) | 3.4% | — | 11 jun 2024 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2024-20670 | Alta (8.1) | 2.3% | — | 9 abr 2024 | Outlook for Windows Spoofing Vulnerability |
| CVE-2024-26204 | Alta (7.5) | 2.1% | — | 12 mar 2024 | Outlook for Android Information Disclosure Vulnerability |
| CVE-2024-21378 | Alta (8.8) | 11% | — | 13 feb 2024 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2023-36763 | Alta (7.5) | 2.1% | — | 12 sept 2023 | Microsoft Outlook Information Disclosure Vulnerability |
| CVE-2023-36893 | Media (6.5) | 2.2% | — | 8 ago 2023 | Microsoft Outlook Spoofing Vulnerability |
| CVE-2023-35311 | Alta (7.5) | 16% | ⚠ Explotación activa | 11 jul 2023 | Microsoft Outlook Security Feature Bypass Vulnerability |
| CVE-2023-33131 | Alta (8.8) | 5.7% | — | 14 jun 2023 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2022-35742 | Alta (7.5) | 22% | — | 1 jun 2023 | Microsoft Outlook Denial of Service Vulnerability |
| CVE-2023-23397 | Crítica (9.8) | 97% | ⚠ Explotación activa | 14 mar 2023 | Microsoft Outlook Elevation of Privilege Vulnerability |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.