Outlook for Android Elevation of Privilege Vulnerability
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.7epss 1.1%
exploitation probability
1.1%top 38% of all CVEs
observed exploitation
nono source reports it
In short
A vulnerability in Outlook for Android allows an attacker to gain elevated privileges on the device. An attacker with access to the device could exploit this flaw to perform actions that normally require higher permissions.
Technical detail
CWE-1220 indicates improper restriction of rendered UI layers or frames, allowing privilege escalation through UI-based attacks. An attacker with local or physical access to the affected device can bypass permission boundaries in Outlook for Android to execute operations with elevated privileges.
Summary generated and translated by AI from the official description.
Outlook for Android Elevation of Privilege Vulnerability
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Affected products
Microsoft · Microsoft Outlook for Android