Skip to main content

Microsoft Outlook has a new ‘critical’ flaw that spreads malware easily

Outlook running on the Samsung Galaxy Z Flip 5 cover screen.
Outlook app on the Z Flip 5 cover screen Joe Maring / Digital Trends

In a security alert, Microsft warned users how easy it is for hackers to distribute malware using their Outlook email client. Microsoft has already released a patch for the CVE-2025-21298 user-after-free vulnerability and urges users to apply it immediately.

Microsoft gave the vulnerability a severity score of 9.8 (critical) since it uses freed memory and corrupts valid data, or parcels out malware remotely. This bug is in the Windows Object Linking and Embedding (OLED) function, allowing you to embed and link to documents and other objects, such as adding an Excel chart to a Word document. It’s so dangerous that you can become infected by previewing the specially crafted email.

Recommended Videos

Microsoft said in the security warning, “Exploitation of the vulnerability might involve either a victim opening a specially crafted email with an affected version of Microsoft Outlook software, or a victim’s Outlook application displaying a preview of a specially crafted email. This could result in the attacker executing remote code on the victim’s machine.”

If you can’t apply the patch at the moment, Microsoft encourages you to apply tips such as viewing your emails in large LAN networks as plain text and turning off or restricting NTLM traffic altogether. What happens when you view your emails in plain text? Basically, all animation, images, and different fonts are removed. Your emails won’t look as stylish when viewing them in plain text, but this way, you can avoid loss of customers, business disruptions, and possibly regulatory fines.

No app is perfect and you’ll come across issues sooner or later. Even Outlook has common problems but if your facing some basic issues, we’ve got you covered on how to fix them. This isn’t the first major issue Outlook has faced with hackers being able to view emails a while back.

Judy Sanhz
Computing Writer
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
Microsoft confirms Classic Outlook typing issue causing CPU spikes
Outlook.com

In a post on Microsoft's Support blog, the company warns that typing in a recent version of classic Outlook can lead to high CPU usage. The issue could cause CPU usage to spike by up to 50%, and the company recommends switching to the Microsoft 365 Apps update channel as a temporary workaround.

The problems occur when composing an email in Version 2406 (Build 17726.20126) on the Current Channel, Monthly Enterprise Channel, or Insider Channels. Affected users report CPU usage increases between 20% and 50%, which can also raise power consumption. Microsoft says the Outlook team is investigating and will provide further updates as they become available.

Read more
Windows 11 users outsmart Microsoft once again with new local account trick
A screenshot of the Windows 11 Microsoft Account setup page

A newly discovered trick allows Windows 11 users to bypass Microsoft’s online account requirement during setup, raising questions around user control and privacy. The workaround, shared by X user @witherornot1337, lets users set up Windows 11 with a local account instead of being forced to log in with a Microsoft account.

This follows previous similar methods, highlighting an ongoing cat-and-mouse game between Microsoft and privacy-conscious users. Microsoft has been increasingly pushing online accounts as a mandatory requirement for Windows 11, particularly in Home and Pro editions. This change has frustrated many users who prefer local accounts for greater privacy and independence from Microsoft’s ecosystem.

Read more
Microsoft is working on something new, but it’s probably not Windows 12
The Surface Pro 11 on a white table in front of a window.

Microsoft appears to be working on a new major update, but if you're hoping for Windows 12, I wouldn't hold my breath. The company has confirmed that it's testing new content via the Insider program in the Dev Channel, and those changes might lead to a patch that's set to be released later this year. However, we're most likely looking at the successor to the current 24H2 build -- namely Windows 11 25H2 -- and not a whole new operating system.

This was first spotted by Windows Central. The publication cites its own sources as it claims that Microsoft is backporting some platform changes to offer better support for Qualcomm's upcoming Snapdragon X2 chip. Those changes will allow devices that house that chip to run Germanium-based Windows 11. Germanium refers to the platform release that the current Windows 11 build is built on, and it looks like the upcoming 25H2 build might also be based on Germanium -- but nothing is fully clear at this point.

Read more