Skip to main content

Microsoft Outlook has a new ‘critical’ flaw that spreads malware easily

Outlook running on the Samsung Galaxy Z Flip 5 cover screen.
Outlook app on the Z Flip 5 cover screen Joe Maring / Digital Trends

In a security alert, Microsft warned users how easy it is for hackers to distribute malware using their Outlook email client. Microsoft has already released a patch for the CVE-2025-21298 user-after-free vulnerability and urges users to apply it immediately.

Microsoft gave the vulnerability a severity score of 9.8 (critical) since it uses freed memory and corrupts valid data, or parcels out malware remotely. This bug is in the Windows Object Linking and Embedding (OLED) function, allowing you to embed and link to documents and other objects, such as adding an Excel chart to a Word document. It’s so dangerous that you can become infected by previewing the specially crafted email.

Recommended Videos

Microsoft said in the security warning, “Exploitation of the vulnerability might involve either a victim opening a specially crafted email with an affected version of Microsoft Outlook software, or a victim’s Outlook application displaying a preview of a specially crafted email. This could result in the attacker executing remote code on the victim’s machine.”

If you can’t apply the patch at the moment, Microsoft encourages you to apply tips such as viewing your emails in large LAN networks as plain text and turning off or restricting NTLM traffic altogether. What happens when you view your emails in plain text? Basically, all animation, images, and different fonts are removed. Your emails won’t look as stylish when viewing them in plain text, but this way, you can avoid loss of customers, business disruptions, and possibly regulatory fines.

No app is perfect and you’ll come across issues sooner or later. Even Outlook has common problems but if your facing some basic issues, we’ve got you covered on how to fix them. This isn’t the first major issue Outlook has faced with hackers being able to view emails a while back.

Judy Sanhz
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
Microsoft introduces new ‘pay-as-you-go’ AI agents
microsoft copilot introduce ai agents free enterprise subscription tier m365 465350 blog 250110 1 1260

Microsoft will begin offering access to AI agents — specialized generative models that can operate independently and automate repetitive daily tasks — to enterprise users. The new program is called Microsoft 365 Copilot Chat and offers "pay-as-you-go agents to our existing free chat experience for Microsoft 365 commercial customers," the company announced Wednesday.

The "free plus metered agent usage" Microsoft 365 Copilot Chat offers many of the same features as the existing $30 per user per month "Microsoft 365 Copilot" enterprise program, including access to a chatbot powered by GPT-4o, Copilot Pages, file uploads, image and code generation, enterprise data protection, and, of course, to Copilot Studio, where individual users and IT departments alike can create AI agents. Note, however, that the free Chat program does not grant you access to the Copilot personal assistant, which integrates the AI's capabilities into the rest of the 365 Copilot app ecosystem such as Word, Outlook, and Excel.

Read more
Microsoft’s new ergonomic keyboard has ‘ultra-responsive’ keys
Microsoft Ergonomic Keyboard

Just when you thought you were done shopping for now, Incase, the manufacturer of the Microsoft accessory line, revealed a new compact yet expensive keyboard on its website. The ergonomic keyboard offers solid specs, but the high price tag might make some potential buyers think twice about getting it.

It offers "ultra-responsive" scissor keys with 1.3mm travel, allowing you to type without pressing the keys too hard. Incase claims you can sync up to three devices to the Microsoft keyboard with Bluetooth 4.0, but you will need two AAA batteries that Incase claims will last 36 months. As a perk, the batteries come bundled with the keyboard, so you won't have to buy them separately.

Read more
A new test shows Microsoft Recall’s continued security problems
Recall screenshot.

Microsoft is currently previewing its latest version of Recall to Windows Insiders on Snapdragon-, Intel-, and AMD-based Copilot+ PCs -- and the topic on most users' minds is security. The company updated its security and privacy architecture for the feature in September, but, according to tests run by Tom's Hardware, it still might not be good enough.

The new version of Recall includes a sensitive information filter that's supposed to detect when there's information like credit card numbers and Social Security numbers on the screen. If it detects them, it will avoid taking a screenshot. When Tom's Hardware put this filter to the test, however, it failed in a number of situations.

Read more