CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

microsoft

outlook

53 known vulnerabilities · sorted by CVSS score

CVE-2023-23397
CRITICAL9.8

Microsoft Outlook Elevation of Privilege Vulnerability

microsoft / 365_apps+5
Network
Published Mar 14, 2023
Page 1 of 3
CVE-2018-0851
HIGH8.8

Microsoft Office 2007 SP2, Microsoft Office Word Viewer, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Office handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0852.

microsoft / office+7
Network
Published Feb 15, 2018
CVE-2023-33131
HIGH8.8

Microsoft Outlook Remote Code Execution Vulnerability

microsoft / office+8
Network
Published Jun 14, 2023
CVE-2023-35311
HIGH8.8

Microsoft Outlook Security Feature Bypass Vulnerability

microsoft / 365_apps+5
Network
Published Jul 11, 2023
CVE-2018-8582
HIGH8.8

A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export files, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8522, CVE-2018-8524, CVE-2018-8576.

microsoft / office_365_proplus+5
Network
Published Nov 14, 2018
CVE-2024-30103
HIGH8.8

Microsoft Outlook Remote Code Execution Vulnerability

microsoft / 365_apps+7
Network
Published Jun 11, 2024
CVE-2018-0852
HIGH8.8

Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1 and RT SP1, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Outlook handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0851.

microsoft / office+5
Network
Published Feb 15, 2018
CVE-2024-21378
HIGH8.8

Microsoft Outlook Remote Code Execution Vulnerability

microsoft / 365_apps+3
Network
Published Feb 13, 2024
CVE-2020-0760
HIGH8.8

A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.

microsoft / access+32
Network
Published Apr 15, 2020
CVE-2024-20670
HIGH8.1

Outlook for Windows Spoofing Vulnerability

microsoft / outlook
Network
Published Apr 9, 2024
CVE-2018-8524
HIGH7.8

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8522, CVE-2018-8576, CVE-2018-8582.

microsoft / office+5
Local
Published Nov 14, 2018
CVE-2025-21361
HIGH7.8

Microsoft Outlook Remote Code Execution Vulnerability

microsoft / office+2
Local
Published Jan 14, 2025
CVE-2020-1349
HIGH7.8

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.

microsoft / 365_apps+5
Local
Published Jul 14, 2020
CVE-2018-0791
HIGH7.8

Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, and Microsoft Outlook 2016 allow a remote code execution vulnerability due to the way email messages are parsed, aka "Microsoft Outlook Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0793.

microsoft / office+5
Local
Published Jan 10, 2018
CVE-2018-8522
HIGH7.8

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8524, CVE-2018-8576, CVE-2018-8582.

microsoft / office+5
Local
Published Nov 14, 2018
CVE-2019-1200
HIGH7.8

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user. To exploit the vulnerability, a user must open a specially crafted file with an affected version of Microsoft Outlook software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability. However, an attacker would have no way to force the user to visit the website. Instead, an attacker would have to convince the user to click a link, typically by way of an enticement in an email or Instant Messenger message, and then convince the user to open the specially crafted file. Note that the Preview Pane is not an attack vector for this vulnerability. The security update addresses the vulnerability by correcting how Microsoft Outlook handles files in memory.

microsoft / office+5
Local
Published Aug 14, 2019
CVE-2021-31941
HIGH7.8

Microsoft Office Graphics Remote Code Execution Vulnerability

microsoft / 365_apps+6
Local
Published Jun 8, 2021
CVE-2018-8576
HIGH7.8

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8522, CVE-2018-8524, CVE-2018-8582.

microsoft / office+5
Local
Published Nov 14, 2018
CVE-2025-29805
HIGH7.5

Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.

microsoft / outlook
Network
Published Apr 8, 2025
CVE-2023-36763
HIGH7.5

Microsoft Outlook Information Disclosure Vulnerability

microsoft / 365_apps+7
Network
Published Sep 12, 2023