Integer Overflow Vulnerability in Microsoft Outlook
CVE-2026-70329
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 11 August 2026
Badges
What is CVE-2026-70329?
CVE-2026-70329 is an integer overflow vulnerability identified in Microsoft Outlook, a widely used email and personal information management application. This vulnerability arises from the mishandling of integer values, potentially allowing unauthorized attackers to execute arbitrary code over a network. The implications of such a flaw can be severe for organizations, particularly as Outlook is integral to communication and collaboration tasks. If left unaddressed, this vulnerability could enable attackers to gain unauthorized access to sensitive data or systems through compromised Outlook clients, leading to significant disruption and data loss.
Potential Impact of CVE-2026-70329
-
Unauthorized Code Execution: The primary risk associated with CVE-2026-70329 is that it allows attackers to execute arbitrary code on affected systems. This could lead to the installation of malware, data exfiltration, or other malicious activities without user consent.
-
Data Breaches: Exploiting this vulnerability could result in unauthorized access to sensitive organizational data contained within emails and attachments, potentially leading to severe data breaches and compliance violations.
-
Network Compromise: As Outlook is often integrated with organizational networks, successful exploitation of this vulnerability could allow attackers to pivot and access other systems within the network, thereby escalating their attack and increasing the overall impact on the organization.
Affected Version(s)
Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1
Microsoft Office 2019 32-bit Systems 19.0.0
Microsoft Office LTSC 2021 32-bit Systems 16.0.1
News Articles
Microsoft Outlook Vulnerability Allows Attackers to Execute Malicious Code Remotely - IT Security News
2026-08-12 06:08 Microsoft has disclosed a new remote code execution flaw in Outlook, tracked as CVE-2026-70329, as part of its August 2026 Patch Tuesday rollout. The vulnerability stems from...
2 days ago
Microsoft Outlook Vulnerability Allows Attackers to Execute Malicious Code Remotely
Microsoft has disclosed a new remote code execution flaw in Outlook, tracked as CVE-2026-70329, as part of its August 2026 Patch Tuesday rollout.
2 days ago

References
CVSS V3.1
Timeline
- πΎ
Exploit known to exist
- π°
First article discovered by Cybersecuritynews
Vulnerability published
Vulnerability Reserved