A Security Update has been released for Outlook 2016. It resolves the following vulnerability;
- CVE-2024-30103: Microsoft Outlook Remote Code Execution Vulnerability
- This vulnerability is currently not publicly disclosed nor exploited.
- Exploitation of the vulnerability requires the attacker to be authenticated using valid Exchange user credentials.
- An attacker who successfully exploited this vulnerability could bypass Outlook registry block lists and enable the creation of malicious DLL files.
- The Preview Pane is an attack vector.
- The Exploitability Assessment is rated: Exploitation Less Likely.
View: Download information for KB5002600
Note: This update can be installed via Microsoft Update and updates Outlook to version 16.0.5450.1000. This update does not apply to Perpetual (Retail) and Microsoft 365 based installations of Office 2016.