CVE-2025-21298
Microsoft · Published January 14, 2025
9.8
CVSS v3.1
CRITICALPatch availableGet patch
Description
Windows OLE remote code execution via specially crafted Rich Text Format (RTF) emails. Opening or previewing the email in Outlook triggers the vulnerability without user interaction beyond email receipt.
Affected Products
- Windows 10/11 (all versions)
- Windows Server 2016/2019/2022/2025
- Microsoft Outlook (all current versions)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H