- Description
- Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- Source
- secure@microsoft.com
- NVD status
- Modified
- Products
- 365_apps, office, office_long_term_servicing_channel, word
CVSS 3.1
- Type
- Secondary
- Base score
- 8.4
- Impact score
- 5.9
- Exploitability score
- 2.5
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-416
- Hype score
- Not currently trending
CVE-2026-40361 | Microsoft Outlook and Word Remote Code Execution Vulnerability | R.A.H.S.I. Framework™ https://t.co/pnSMYqAixs https://t.co/sL8igJVBTv
@rahsi_aaka
5 Jun 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
📰 Newsletter RadioCSIRT, N°54 Au sommaire de la semaine du 9 au 15 mai 2026 : famille Dirty Frag (CVE-2026-43284 / 43500), YellowKey contre BitLocker, CVE-2026-40361 zero-click Outlook, AMD-SB-7052, Shai-Hulud, et bien plus. https://t.co/fSsRlrZgPs ⚡ On ne réfléchi
@marcfredericgo
16 May 2026
92 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
💥 Outlook - Faille zéro clic Le Patch Tuesday de mai 2026 publié par Microsoft corrige une faille de type zero-click affectant Outlook (et Word) : CVE-2026-40361. Voici comment se protéger. - https://t.co/o0wmbHpHk5 #outlook #infosec #microsoft https://t.co/zxxc5y2324
@ITConnect_fr
16 May 2026
1033 Impressions
7 Retweets
16 Likes
3 Bookmarks
0 Replies
0 Quotes
「2025年5月に提供された「CVE-2026-40361」 の修正プログラム」#パソコンのツボ https://t.co/1hs94z6yM0
@pcclick007
15 May 2026
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔐 セキュリティトレンド (14:53 JST) ① 「Windows Server 2025」に問題、ブルースクリーンでメモリダンプが生成されない/2026年5月 ... https://t.co/pos7xkKGHw ② Outlook ゼロクリック脆弱性 CVE-2026-40361|メール閲覧だけ
@kenebeii
14 May 2026
102 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【Microsoft CVE-2026-40361、OutlookゼロクリックRCEとして優先パッチ対象】 Microsoftの2026年5月月例更新で修正されたCVE-2026-40361は、Outlook/Word関連のCritical
@01ra66it
14 May 2026
435 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
microsoft CVE-2026-40361: RCE. patch tuesday came early. assume mass scanning starts within 48h. #Microsoft #RCE #AIsecurity #CVE-2026-40361 https://t.co/0A8e5X9RX8
@trerbbb
13 May 2026
101 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
18:33 UTC: CVE-2026-40361 disclosed. CVE-2026-40361 ( patched today, is a critical 0-click UAF/RCE bug in Microsoft Outlook that I d 0day Intel: CVE-2026-40361 (https://t.co/osGIhRwvVi), patched today, is a critical 0-click U
@lyrie_ai
13 May 2026
78 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
9 new OPEN, 16 new PRO (9 + 7) DOILoader, Outlook Classic Use After Free Remote Code Execution Attempt (CVE-2026-40361), Rclone (CVE-2026-41176, CVE-2026-41179), TA569, Win32/Lumma Stealer https://t.co/aOnlJCYCq8
@ET_Labs
12 May 2026
219 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*",
"matchCriteriaId": "3259EBFE-AE2D-48B8-BE9A-E22BBDB31378",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*",
"matchCriteriaId": "CD25F492-9272-4836-832C-8439EBE64CCF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x64:*",
"matchCriteriaId": "CF5DDD09-902E-4881-98D0-CB896333B4AA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:x86:*",
"matchCriteriaId": "26A3B226-5D7C-4556-9350-5222DC8EFC2C",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x64:*",
"matchCriteriaId": "851BAC4E-9965-4F40-9A6C-B73D9004F4C1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:-:x86:*",
"matchCriteriaId": "23B2FA23-76F4-4D83-A718-B8D04D7EA37B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:macos:*:*",
"matchCriteriaId": "BF0E8112-5B6F-4E55-8E40-38ADCF6FC654",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x64:*",
"matchCriteriaId": "D31E509A-0B2E-4B41-88C4-0099E800AFE6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:-:x86:*",
"matchCriteriaId": "017A7041-BEF1-4E4E-AC8A-EFC6AFEB01FE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2024:*:*:*:*:macos:*:*",
"matchCriteriaId": "EF3E56B5-E6A6-4061-9380-D421E52B9199",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x64:*",
"matchCriteriaId": "E1FE9E95-4874-46EF-AC93-9E485F7A2AC0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x86:*",
"matchCriteriaId": "38479B5D-66F9-4260-A18A-F6E3D9B6991E",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]