CVE-2025-21259HighCVSS 5.3

Microsoft Outlook Spoofing Vulnerability

Published
June 3, 2026
Last Modified

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability? An attacker's message can inherit the sender's email address from another message in the UI. The attacker cannot control which message it inherits from. This issue occurs exclusively for messages in the Junk folder, as it is the only folder where the app displays the sender's email address. The attacker cannot affect confidentiality or availability.

🎯 Affected products1

  • Microsoft Outlook for Android

✅ Remediation

KBRelease Notes (Security Update) — fixed build 4.2501.1

🔗 References (3)