Important EPSS 0.01817 2019-06 archive

Executive Summary

A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim. The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on the affected systems and run scripts in the security context of the current user. The security update addresses the vulnerability by correcting how Outlook for Android parses specially crafted email messages.

Overview

Important
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
Category Spoofing
Released Jun 11 2019
Last Updated Jun 11 2019
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.01817 — 0.75897 percentile

EPSS Score

0.01817
probability of exploitation in the next 30 days
0.75897 percentile - updated 2026-06-20
View on FIRST.org

Affected Products

1 affected product
Product KB Article Severity Impact Restart Required
Microsoft Outlook for Android Release Notes (Security Update) Important Spoofing Maybe

Patches

1 patch
Article Type Restart
Release Notes Security Update Maybe

Known Exploits

Acknowledgments

Sander Vanrapenbusch, Gaurav Kumar(0x01) @kumargaurav776, Bryan Appleby F5 Networks, Eliraz Duek, Or Ida, Nethanel Coppenhagen | CyberArk, Tom Wyckhuys