Microsoft patched a critical Microsoft Office vulnerability, tracked as CVE-2025-30377, that can allow remote code execution when a specially crafted email attachment is processed in Outlook’s Preview Pane. The flaw was described as a use-after-free memory corruption issue tied to improper pointer management in Office, and exploitation reportedly requires little to no user interaction, making it effectively a zero-click threat during normal email handling.
Affected products reportedly included Microsoft 365 Apps, Office 2016 through Office 2024, and Office Online Server 2019 through 2025 before the May 2025 security updates. Security guidance urged organizations to deploy Microsoft’s patches quickly, consider temporarily disabling Outlook preview features, strengthen email filtering, and monitor for unusual Office process behavior, suspicious attachments, and anomalous email or authentication activity because successful exploitation could enable malware installation, credential theft, unauthorized access, and wider enterprise compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft addressed CVE-2025-30377, a critical Microsoft Office remote code execution flaw exploitable via Outlook's Preview Pane, in its May 2025 Patch Tuesday updates. Affected products included Microsoft 365 Apps, Office 2016 through Office 2024, and Office Online Server versions 2019 through 2025 prior to the patch.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.