Attackers Can Exploit Microsoft Outlook and Word Flaws to Run Malicious Code
ID: 340e1782-701e-58eb-a5ce-75d72c591ea6
STIX ID: report--340e1782-701e-58eb-a5ce-75d72c591ea6
Feed Name: GBHackers
Microsoft disclosed three critical RCE vulnerabilities in Outlook and Word (CVE-2026-45456, CVE-2026-45458, CVE-2026-47635) rated with high severity (CVSS ~8.4). The flaws — a type confusion, a use-after-free, and a heap-based buffer overflow — can be exploited via specially crafted documents or phishing emails to achieve arbitrary code execution without privileges or user interaction; organizations are urged to apply patches immediately and implement mitigations such as disabling Outlook preview panes, tightening email filtering, and monitoring with EDR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
