#VU66320 Heap-based buffer overflow in Microsoft products - CVE-2022-35742
Published: August 9, 2022 / Updated: August 18, 2022
Microsoft Outlook
Microsoft Office
Microsoft 365 Apps for Enterprise
Microsoft Office LTSC
Microsoft
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in Microsoft Outlook when handling MIME headers. A remote attacker can send a specially crafted email to the victim and trigger heap corruption every time the email is processed by the application.
Successful exploitation may result in a perform a persistent denial-of-service condition.