{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/cve-2026-70329-microsoft-outlook-rce-patch-guidance/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/cve-2026-70329-microsoft-outlook-rce-patch-guidance/",
        "slug": "cve-2026-70329-microsoft-outlook-rce-patch-guidance",
        "url": "https://update.dsesecurity.com/updates/cve-2026-70329-microsoft-outlook-rce-patch-guidance/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/cve-2026-70329-microsoft-outlook-rce-patch-guidance.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/cve-2026-70329-microsoft-outlook-rce-patch-guidance/"
        },
        "title": "CVE-2026-70329 in Outlook: What the 8.8 RCE Means and How to Respond",
        "summary": "Microsoft has fixed CVE-2026-70329, an Outlook integer-overflow vulnerability rated CVSS 8.8. Exploitation requires a user to open a malicious Office file. Review the exact affected editions, deploy the August 11 security release, and verify the installed build by servicing channel.",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "Gavin Stewart",
            "url": "https://www.linkedin.com/in/gavin-stewart-0718/",
            "type": "Person"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-12T15:47:15+00:00",
        "modified_at": "2026-08-12T15:47:15+00:00",
        "reviewed_on": "2026-08-12",
        "reading_minutes": 5,
        "word_count": 1035,
        "potentially_affected": "Microsoft 365 Apps for Enterprise, Office 2019, Office LTSC 2021, Office LTSC 2024, and Outlook 2016 on Windows, in the 32-bit and 64-bit editions listed by Microsoft.",
        "dse_recommendation": "Inventory Office product, architecture, channel, and build; deploy the August 11, 2026 security update or later; install KB5002755 on MSI-based Outlook 2016; and verify the resulting build on every managed endpoint.",
        "primary_source": {
            "name": "Microsoft Security Response Center (MSRC)",
            "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70329",
            "published_on": "2026-08-11",
            "authority": "msrc.microsoft.com"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>The bottom line</h2>\n<p>Microsoft released security updates on August 11, 2026 for <strong>CVE-2026-70329</strong>, a remote code execution vulnerability in Microsoft Office Outlook caused by an integer overflow or wraparound. Microsoft rates the issue <strong>Important</strong> and assigns it a <strong>CVSS v3.1 base score of 8.8 (High)</strong>.</p>\n<p>This is <strong>not a zero-click vulnerability</strong> based on the information Microsoft has published. An attacker must send a malicious Office file and convince the recipient to open it. That required interaction lowers the likelihood of automatic exploitation, but the potential consequences remain serious: the published CVSS assessment assigns high confidentiality, integrity, and availability impact.</p>\n<p><strong>DSE recommendation:</strong> identify affected Windows Office installations, deploy the appropriate August 11 Office security release or later, and verify the resulting build on each managed update channel. Do not treat email filtering or user awareness as a replacement for the security update.</p>\n\n<h2>What Microsoft has confirmed</h2>\n<ul>\n<li><strong>Vulnerability:</strong> CVE-2026-70329, Microsoft Outlook Remote Code Execution Vulnerability.</li>\n<li><strong>Weakness:</strong> CWE-190, Integer Overflow or Wraparound.</li>\n<li><strong>Severity:</strong> Important under Microsoft&#8217;s rating system; CVSS v3.1 8.8 (High).</li>\n<li><strong>Published vector:</strong> AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</li>\n<li><strong>Required user action:</strong> the recipient must open a malicious Office file supplied by the attacker.</li>\n<li><strong>Customer action:</strong> required. Microsoft has released fixes and does not list a separate workaround.</li>\n</ul>\n<p>The CVSS vector indicates no attacker privileges are required, attack complexity is low, and user interaction is required. Microsoft has not publicly identified the exact file format or parser involved, the code-execution context, or preview-pane exploitation. Claims beyond the published attack path would therefore be speculation.</p>\n\n<h2>Affected products</h2>\n<p>Microsoft&#8217;s affected-product data names the following Windows products in both 32-bit and 64-bit editions:</p>\n<ul>\n<li>Microsoft 365 Apps for Enterprise</li>\n<li>Microsoft Office 2019</li>\n<li>Microsoft Office LTSC 2021</li>\n<li>Microsoft Office LTSC 2024</li>\n<li>Microsoft Outlook 2016</li>\n</ul>\n<p>The advisory does <strong>not</strong> list new Outlook, Outlook on the web, Outlook for Mac, Outlook mobile, Microsoft 365 Apps for Business, or Office 2021/2024 retail as affected products. That omission should not be reversed into a broader claim: scope decisions should follow Microsoft&#8217;s current affected-product table and the actual product installed.</p>\n\n<h2>Fixed builds published for August 11</h2>\n<p>For Click-to-Run and volume-licensed Office deployments, administrators should use Microsoft&#8217;s Office security-release table to match the installed servicing channel to the correct secured build. The fixed builds published on August 11, 2026 include:</p>\n<table>\n<thead><tr><th>Office channel or product</th><th>Security build</th></tr></thead>\n<tbody>\n<tr><td>Microsoft 365 Current Channel</td><td>Version 2607, build 20228.20190</td></tr>\n<tr><td>Monthly Enterprise Channel</td><td>2607 / 20228.20188; 2606 / 20131.20206; 2605 / 20026.20266</td></tr>\n<tr><td>Semi-Annual Enterprise Channel receiving Monthly Enterprise builds</td><td>2607 / 20228.20186</td></tr>\n<tr><td>Semi-Annual Enterprise Channel</td><td>2508 / 19127.20730</td></tr>\n<tr><td>Office LTSC 2024 Volume Licensed</td><td>2408 / 17932.20910</td></tr>\n<tr><td>Office LTSC 2021 Volume Licensed</td><td>2108 / 14334.20848</td></tr>\n<tr><td>Office 2019 Volume Licensed</td><td>1808 / 10417.20197</td></tr>\n<tr><td>Outlook 2016 MSI</td><td>KB5002755; fixed build 16.0.5565.1000</td></tr>\n</tbody>\n</table>\n<p>Microsoft says the Click-to-Run security updates do not require a restart. The Outlook 2016 MSI update may require one. <a href=\"https://support.microsoft.com/kb/5002755\">KB5002755</a> applies to the MSI-based edition of Outlook 2016, not the Click-to-Run edition.</p>\n<p>Office 2019 and Outlook 2016 reached end of support on October 14, 2025. Microsoft nevertheless published the relevant August 2026 fixes. Organizations still operating these versions should install the released security update and maintain a supported-version migration plan; the availability of this update does not restore full product support.</p>\n\n<h2>How the attack path changes the response</h2>\n<p>The confirmed attack path begins with a malicious Office file delivered to a user and succeeds only if the user opens it. That makes email, collaboration platforms, downloads, and other file-delivery paths relevant control points, but it does not make patching optional.</p>\n<p>Until every affected installation is updated, DSE recommends treating unexpected Office attachments and links to Office documents as untrusted, maintaining attachment scanning and endpoint detection controls, and prioritizing users who routinely process external documents. These are <strong>DSE operational precautions</strong> derived from the published attack path; Microsoft has not published them as a formal workaround.</p>\n\n<h2>A practical patch-and-verify plan</h2>\n<ol>\n<li><strong>Inventory the actual Office estate.</strong> Record product, architecture, update technology, servicing channel, and current build. Do not rely only on a generic “Office installed” result.</li>\n<li><strong>Prioritize exposed workflows.</strong> Start with users and teams that frequently open documents from customers, vendors, public mailboxes, file-transfer portals, or other external sources.</li>\n<li><strong>Deploy the correct release.</strong> Use the August 11 Office security update for the installed servicing channel. For MSI-based Outlook 2016, deploy KB5002755.</li>\n<li><strong>Verify the installed build.</strong> Confirm the resulting version against Microsoft&#8217;s channel-specific security table. A deployment job marked successful is not proof that the intended Office build is active.</li>\n<li><strong>Monitor exceptions.</strong> Track endpoints that are offline, held by update rings, failing health checks, or running end-of-support Office versions. Give every exception an owner and due date.</li>\n<li><strong>Investigate suspicious opens.</strong> If a user opened an unexpected Office file before the update, preserve the message and file metadata and review endpoint and email-security telemetry using the organization&#8217;s incident-response process.</li>\n</ol>\n\n<h2>Exploitation status as of August 12, 2026</h2>\n<p>At publication, Microsoft reported the vulnerability as <strong>not publicly disclosed</strong>, <strong>not exploited</strong>, and assessed exploitation as <strong>unlikely</strong>. CISA&#8217;s CVE enrichment records exploitation as “none,” and CVE-2026-70329 was not listed in CISA&#8217;s Known Exploited Vulnerabilities catalog when DSE checked on August 12.</p>\n<p>Those are dated status statements, not guarantees about future activity. The presence of an official fix, the 8.8 score, and the potential for high impact support prompt remediation even without confirmed exploitation.</p>\n\n<h2>A note about Microsoft&#8217;s attack-vector wording</h2>\n<p>Microsoft&#8217;s published CVSS vector and the CVE Program record list the attack vector as <strong>Network (AV:N)</strong>, and the CNA description says code execution is possible “over a network.” One sentence in Microsoft&#8217;s FAQ, however, refers to <strong>Local (AV:L)</strong>. The same FAQ clearly states that the attacker sends a malicious file and the recipient must open it.</p>\n<p>The most defensible description from the available source material is therefore: <strong>the malicious file can be delivered over a network, but exploitation requires the recipient to open it locally</strong>. DSE is not using the inconsistent FAQ sentence to infer a different exploit path and recommends monitoring the MSRC page for revisions.</p>\n\n<h2>Primary sources</h2>\n<ul>\n<li><a href=\"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70329\">Microsoft Security Response Center: CVE-2026-70329</a> — severity, CVSS, affected products, attack requirements, and vendor exploitation assessment.</li>\n<li><a href=\"https://www.cve.org/CVERecord?id=CVE-2026-70329\">CVE Program record for CVE-2026-70329</a> — published CNA record and CISA ADP enrichment.</li>\n<li><a href=\"https://learn.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates\">Microsoft Office security releases</a> — August 11, 2026 fixed builds by Office servicing channel.</li>\n<li><a href=\"https://support.microsoft.com/kb/5002755\">Microsoft KB5002755 for Outlook 2016</a> — MSI package applicability and update details.</li>\n<li><a href=\"https://www.cisa.gov/known-exploited-vulnerabilities-catalog\">CISA Known Exploited Vulnerabilities Catalog</a> — checked August 12, 2026 for current KEV status.</li>\n<li><a href=\"https://learn.microsoft.com/en-us/lifecycle/announcements/october-14-2025-products-end-of-support\">Microsoft lifecycle notice for products ending support October 14, 2025</a> — Office 2019 and Office 2016 lifecycle context.</li>\n</ul>\n<p><em>Reviewed August 12, 2026. Vendor guidance and exploitation status can change; use the linked Microsoft advisory as the controlling source for later revisions.</em></p>",
        "content_text": "The bottom line\nMicrosoft released security updates on August 11, 2026 for CVE-2026-70329, a remote code execution vulnerability in Microsoft Office Outlook caused by an integer overflow or wraparound. Microsoft rates the issue Important and assigns it a CVSS v3.1 base score of 8.8 (High).\nThis is not a zero-click vulnerability based on the information Microsoft has published. An attacker must send a malicious Office file and convince the recipient to open it. That required interaction lowers the likelihood of automatic exploitation, but the potential consequences remain serious: the published CVSS assessment assigns high confidentiality, integrity, and availability impact.\nDSE recommendation: identify affected Windows Office installations, deploy the appropriate August 11 Office security release or later, and verify the resulting build on each managed update channel. Do not treat email filtering or user awareness as a replacement for the security update.\n\nWhat Microsoft has confirmed\n\nVulnerability: CVE-2026-70329, Microsoft Outlook Remote Code Execution Vulnerability.\nWeakness: CWE-190, Integer Overflow or Wraparound.\nSeverity: Important under Microsoft’s rating system; CVSS v3.1 8.8 (High).\nPublished vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.\nRequired user action: the recipient must open a malicious Office file supplied by the attacker.\nCustomer action: required. Microsoft has released fixes and does not list a separate workaround.\n\nThe CVSS vector indicates no attacker privileges are required, attack complexity is low, and user interaction is required. Microsoft has not publicly identified the exact file format or parser involved, the code-execution context, or preview-pane exploitation. Claims beyond the published attack path would therefore be speculation.\n\nAffected products\nMicrosoft’s affected-product data names the following Windows products in both 32-bit and 64-bit editions:\n\nMicrosoft 365 Apps for Enterprise\nMicrosoft Office 2019\nMicrosoft Office LTSC 2021\nMicrosoft Office LTSC 2024\nMicrosoft Outlook 2016\n\nThe advisory does not list new Outlook, Outlook on the web, Outlook for Mac, Outlook mobile, Microsoft 365 Apps for Business, or Office 2021/2024 retail as affected products. That omission should not be reversed into a broader claim: scope decisions should follow Microsoft’s current affected-product table and the actual product installed.\n\nFixed builds published for August 11\nFor Click-to-Run and volume-licensed Office deployments, administrators should use Microsoft’s Office security-release table to match the installed servicing channel to the correct secured build. The fixed builds published on August 11, 2026 include:\n\nOffice channel or productSecurity build\n\nMicrosoft 365 Current ChannelVersion 2607, build 20228.20190\nMonthly Enterprise Channel2607 / 20228.20188; 2606 / 20131.20206; 2605 / 20026.20266\nSemi-Annual Enterprise Channel receiving Monthly Enterprise builds2607 / 20228.20186\nSemi-Annual Enterprise Channel2508 / 19127.20730\nOffice LTSC 2024 Volume Licensed2408 / 17932.20910\nOffice LTSC 2021 Volume Licensed2108 / 14334.20848\nOffice 2019 Volume Licensed1808 / 10417.20197\nOutlook 2016 MSIKB5002755; fixed build 16.0.5565.1000\n\nMicrosoft says the Click-to-Run security updates do not require a restart. The Outlook 2016 MSI update may require one. KB5002755 applies to the MSI-based edition of Outlook 2016, not the Click-to-Run edition.\nOffice 2019 and Outlook 2016 reached end of support on October 14, 2025. Microsoft nevertheless published the relevant August 2026 fixes. Organizations still operating these versions should install the released security update and maintain a supported-version migration plan; the availability of this update does not restore full product support.\n\nHow the attack path changes the response\nThe confirmed attack path begins with a malicious Office file delivered to a user and succeeds only if the user opens it. That makes email, collaboration platforms, downloads, and other file-delivery paths relevant control points, but it does not make patching optional.\nUntil every affected installation is updated, DSE recommends treating unexpected Office attachments and links to Office documents as untrusted, maintaining attachment scanning and endpoint detection controls, and prioritizing users who routinely process external documents. These are DSE operational precautions derived from the published attack path; Microsoft has not published them as a formal workaround.\n\nA practical patch-and-verify plan\n\nInventory the actual Office estate. Record product, architecture, update technology, servicing channel, and current build. Do not rely only on a generic “Office installed” result.\nPrioritize exposed workflows. Start with users and teams that frequently open documents from customers, vendors, public mailboxes, file-transfer portals, or other external sources.\nDeploy the correct release. Use the August 11 Office security update for the installed servicing channel. For MSI-based Outlook 2016, deploy KB5002755.\nVerify the installed build. Confirm the resulting version against Microsoft’s channel-specific security table. A deployment job marked successful is not proof that the intended Office build is active.\nMonitor exceptions. Track endpoints that are offline, held by update rings, failing health checks, or running end-of-support Office versions. Give every exception an owner and due date.\nInvestigate suspicious opens. If a user opened an unexpected Office file before the update, preserve the message and file metadata and review endpoint and email-security telemetry using the organization’s incident-response process.\n\nExploitation status as of August 12, 2026\nAt publication, Microsoft reported the vulnerability as not publicly disclosed, not exploited, and assessed exploitation as unlikely. CISA’s CVE enrichment records exploitation as “none,” and CVE-2026-70329 was not listed in CISA’s Known Exploited Vulnerabilities catalog when DSE checked on August 12.\nThose are dated status statements, not guarantees about future activity. The presence of an official fix, the 8.8 score, and the potential for high impact support prompt remediation even without confirmed exploitation.\n\nA note about Microsoft’s attack-vector wording\nMicrosoft’s published CVSS vector and the CVE Program record list the attack vector as Network (AV:N), and the CNA description says code execution is possible “over a network.” One sentence in Microsoft’s FAQ, however, refers to Local (AV:L). The same FAQ clearly states that the attacker sends a malicious file and the recipient must open it.\nThe most defensible description from the available source material is therefore: the malicious file can be delivered over a network, but exploitation requires the recipient to open it locally. DSE is not using the inconsistent FAQ sentence to infer a different exploit path and recommends monitoring the MSRC page for revisions.\n\nPrimary sources\n\nMicrosoft Security Response Center: CVE-2026-70329 — severity, CVSS, affected products, attack requirements, and vendor exploitation assessment.\nCVE Program record for CVE-2026-70329 — published CNA record and CISA ADP enrichment.\nMicrosoft Office security releases — August 11, 2026 fixed builds by Office servicing channel.\nMicrosoft KB5002755 for Outlook 2016 — MSI package applicability and update details.\nCISA Known Exploited Vulnerabilities Catalog — checked August 12, 2026 for current KEV status.\nMicrosoft lifecycle notice for products ending support October 14, 2025 — Office 2019 and Office 2016 lifecycle context.\n\nReviewed August 12, 2026. Vendor guidance and exploitation status can change; use the linked Microsoft advisory as the controlling source for later revisions.",
        "content_markdown": "## The bottom line\n\nMicrosoft released security updates on August 11, 2026 for CVE-2026-70329, a remote code execution vulnerability in Microsoft Office Outlook caused by an integer overflow or wraparound. Microsoft rates the issue Important and assigns it a CVSS v3.1 base score of 8.8 (High).\n\nThis is not a zero-click vulnerability based on the information Microsoft has published. An attacker must send a malicious Office file and convince the recipient to open it. That required interaction lowers the likelihood of automatic exploitation, but the potential consequences remain serious: the published CVSS assessment assigns high confidentiality, integrity, and availability impact.\n\nDSE recommendation: identify affected Windows Office installations, deploy the appropriate August 11 Office security release or later, and verify the resulting build on each managed update channel. Do not treat email filtering or user awareness as a replacement for the security update.\n\n## What Microsoft has confirmed\n\n- Vulnerability: CVE-2026-70329, Microsoft Outlook Remote Code Execution Vulnerability.\n\n- Weakness: CWE-190, Integer Overflow or Wraparound.\n\n- Severity: Important under Microsoft’s rating system; CVSS v3.1 8.8 (High).\n\n- Published vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.\n\n- Required user action: the recipient must open a malicious Office file supplied by the attacker.\n\n- Customer action: required. Microsoft has released fixes and does not list a separate workaround.\n\nThe CVSS vector indicates no attacker privileges are required, attack complexity is low, and user interaction is required. Microsoft has not publicly identified the exact file format or parser involved, the code-execution context, or preview-pane exploitation. Claims beyond the published attack path would therefore be speculation.\n\n## Affected products\n\nMicrosoft’s affected-product data names the following Windows products in both 32-bit and 64-bit editions:\n\n- Microsoft 365 Apps for Enterprise\n\n- Microsoft Office 2019\n\n- Microsoft Office LTSC 2021\n\n- Microsoft Office LTSC 2024\n\n- Microsoft Outlook 2016\n\nThe advisory does not list new Outlook, Outlook on the web, Outlook for Mac, Outlook mobile, Microsoft 365 Apps for Business, or Office 2021/2024 retail as affected products. That omission should not be reversed into a broader claim: scope decisions should follow Microsoft’s current affected-product table and the actual product installed.\n\n## Fixed builds published for August 11\n\nFor Click-to-Run and volume-licensed Office deployments, administrators should use Microsoft’s Office security-release table to match the installed servicing channel to the correct secured build. The fixed builds published on August 11, 2026 include:\n\nOffice channel or productSecurity build\n\nMicrosoft 365 Current ChannelVersion 2607, build 20228.20190\n\nMonthly Enterprise Channel2607 / 20228.20188; 2606 / 20131.20206; 2605 / 20026.20266\n\nSemi-Annual Enterprise Channel receiving Monthly Enterprise builds2607 / 20228.20186\n\nSemi-Annual Enterprise Channel2508 / 19127.20730\n\nOffice LTSC 2024 Volume Licensed2408 / 17932.20910\n\nOffice LTSC 2021 Volume Licensed2108 / 14334.20848\n\nOffice 2019 Volume Licensed1808 / 10417.20197\n\nOutlook 2016 MSIKB5002755; fixed build 16.0.5565.1000\n\nMicrosoft says the Click-to-Run security updates do not require a restart. The Outlook 2016 MSI update may require one. [KB5002755](https://support.microsoft.com/kb/5002755) applies to the MSI-based edition of Outlook 2016, not the Click-to-Run edition.\n\nOffice 2019 and Outlook 2016 reached end of support on October 14, 2025. Microsoft nevertheless published the relevant August 2026 fixes. Organizations still operating these versions should install the released security update and maintain a supported-version migration plan; the availability of this update does not restore full product support.\n\n## How the attack path changes the response\n\nThe confirmed attack path begins with a malicious Office file delivered to a user and succeeds only if the user opens it. That makes email, collaboration platforms, downloads, and other file-delivery paths relevant control points, but it does not make patching optional.\n\nUntil every affected installation is updated, DSE recommends treating unexpected Office attachments and links to Office documents as untrusted, maintaining attachment scanning and endpoint detection controls, and prioritizing users who routinely process external documents. These are DSE operational precautions derived from the published attack path; Microsoft has not published them as a formal workaround.\n\n## A practical patch-and-verify plan\n\n- Inventory the actual Office estate. Record product, architecture, update technology, servicing channel, and current build. Do not rely only on a generic “Office installed” result.\n\n- Prioritize exposed workflows. Start with users and teams that frequently open documents from customers, vendors, public mailboxes, file-transfer portals, or other external sources.\n\n- Deploy the correct release. Use the August 11 Office security update for the installed servicing channel. For MSI-based Outlook 2016, deploy KB5002755.\n\n- Verify the installed build. Confirm the resulting version against Microsoft’s channel-specific security table. A deployment job marked successful is not proof that the intended Office build is active.\n\n- Monitor exceptions. Track endpoints that are offline, held by update rings, failing health checks, or running end-of-support Office versions. Give every exception an owner and due date.\n\n- Investigate suspicious opens. If a user opened an unexpected Office file before the update, preserve the message and file metadata and review endpoint and email-security telemetry using the organization’s incident-response process.\n\n## Exploitation status as of August 12, 2026\n\nAt publication, Microsoft reported the vulnerability as not publicly disclosed, not exploited, and assessed exploitation as unlikely. CISA’s CVE enrichment records exploitation as “none,” and CVE-2026-70329 was not listed in CISA’s Known Exploited Vulnerabilities catalog when DSE checked on August 12.\n\nThose are dated status statements, not guarantees about future activity. The presence of an official fix, the 8.8 score, and the potential for high impact support prompt remediation even without confirmed exploitation.\n\n## A note about Microsoft’s attack-vector wording\n\nMicrosoft’s published CVSS vector and the CVE Program record list the attack vector as Network (AV:N), and the CNA description says code execution is possible “over a network.” One sentence in Microsoft’s FAQ, however, refers to Local (AV:L). The same FAQ clearly states that the attacker sends a malicious file and the recipient must open it.\n\nThe most defensible description from the available source material is therefore: the malicious file can be delivered over a network, but exploitation requires the recipient to open it locally. DSE is not using the inconsistent FAQ sentence to infer a different exploit path and recommends monitoring the MSRC page for revisions.\n\n## Primary sources\n\n- [Microsoft Security Response Center: CVE-2026-70329](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70329) — severity, CVSS, affected products, attack requirements, and vendor exploitation assessment.\n\n- [CVE Program record for CVE-2026-70329](https://www.cve.org/CVERecord?id=CVE-2026-70329) — published CNA record and CISA ADP enrichment.\n\n- [Microsoft Office security releases](https://learn.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates) — August 11, 2026 fixed builds by Office servicing channel.\n\n- [Microsoft KB5002755 for Outlook 2016](https://support.microsoft.com/kb/5002755) — MSI package applicability and update details.\n\n- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) — checked August 12, 2026 for current KEV status.\n\n- [Microsoft lifecycle notice for products ending support October 14, 2025](https://learn.microsoft.com/en-us/lifecycle/announcements/october-14-2025-products-end-of-support) — Office 2019 and Office 2016 lifecycle context.\n\nReviewed August 12, 2026. Vendor guidance and exploitation status can change; use the linked Microsoft advisory as the controlling source for later revisions."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/cve-2026-70329-microsoft-outlook-rce-patch-guidance/",
                "url": "https://update.dsesecurity.com/updates/cve-2026-70329-microsoft-outlook-rce-patch-guidance/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-12"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/cve-2026-70329-microsoft-outlook-rce-patch-guidance/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "CVE-2026-70329 in Outlook: What the 8.8 RCE Means and How to Respond",
                        "item": "https://update.dsesecurity.com/updates/cve-2026-70329-microsoft-outlook-rce-patch-guidance/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/cve-2026-70329-microsoft-outlook-rce-patch-guidance/#article",
                "identifier": "https://update.dsesecurity.com/updates/cve-2026-70329-microsoft-outlook-rce-patch-guidance/",
                "url": "https://update.dsesecurity.com/updates/cve-2026-70329-microsoft-outlook-rce-patch-guidance/",
                "headline": "CVE-2026-70329 in Outlook: What the 8.8 RCE Means and How to Respond",
                "description": "Microsoft has fixed CVE-2026-70329, an Outlook integer-overflow vulnerability rated CVSS 8.8. Exploitation requires a user to open a malicious Office…",
                "abstract": "Microsoft has fixed CVE-2026-70329, an Outlook integer-overflow vulnerability rated CVSS 8.8. Exploitation requires a user to open a malicious Office file. Review the exact affected editions, deploy the August 11 security release, and verify the installed build by servicing channel.",
                "articleBody": "The bottom line\nMicrosoft released security updates on August 11, 2026 for CVE-2026-70329, a remote code execution vulnerability in Microsoft Office Outlook caused by an integer overflow or wraparound. Microsoft rates the issue Important and assigns it a CVSS v3.1 base score of 8.8 (High).\nThis is not a zero-click vulnerability based on the information Microsoft has published. An attacker must send a malicious Office file and convince the recipient to open it. That required interaction lowers the likelihood of automatic exploitation, but the potential consequences remain serious: the published CVSS assessment assigns high confidentiality, integrity, and availability impact.\nDSE recommendation: identify affected Windows Office installations, deploy the appropriate August 11 Office security release or later, and verify the resulting build on each managed update channel. Do not treat email filtering or user awareness as a replacement for the security update.\n\nWhat Microsoft has confirmed\n\nVulnerability: CVE-2026-70329, Microsoft Outlook Remote Code Execution Vulnerability.\nWeakness: CWE-190, Integer Overflow or Wraparound.\nSeverity: Important under Microsoft’s rating system; CVSS v3.1 8.8 (High).\nPublished vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.\nRequired user action: the recipient must open a malicious Office file supplied by the attacker.\nCustomer action: required. Microsoft has released fixes and does not list a separate workaround.\n\nThe CVSS vector indicates no attacker privileges are required, attack complexity is low, and user interaction is required. Microsoft has not publicly identified the exact file format or parser involved, the code-execution context, or preview-pane exploitation. Claims beyond the published attack path would therefore be speculation.\n\nAffected products\nMicrosoft’s affected-product data names the following Windows products in both 32-bit and 64-bit editions:\n\nMicrosoft 365 Apps for Enterprise\nMicrosoft Office 2019\nMicrosoft Office LTSC 2021\nMicrosoft Office LTSC 2024\nMicrosoft Outlook 2016\n\nThe advisory does not list new Outlook, Outlook on the web, Outlook for Mac, Outlook mobile, Microsoft 365 Apps for Business, or Office 2021/2024 retail as affected products. That omission should not be reversed into a broader claim: scope decisions should follow Microsoft’s current affected-product table and the actual product installed.\n\nFixed builds published for August 11\nFor Click-to-Run and volume-licensed Office deployments, administrators should use Microsoft’s Office security-release table to match the installed servicing channel to the correct secured build. The fixed builds published on August 11, 2026 include:\n\nOffice channel or productSecurity build\n\nMicrosoft 365 Current ChannelVersion 2607, build 20228.20190\nMonthly Enterprise Channel2607 / 20228.20188; 2606 / 20131.20206; 2605 / 20026.20266\nSemi-Annual Enterprise Channel receiving Monthly Enterprise builds2607 / 20228.20186\nSemi-Annual Enterprise Channel2508 / 19127.20730\nOffice LTSC 2024 Volume Licensed2408 / 17932.20910\nOffice LTSC 2021 Volume Licensed2108 / 14334.20848\nOffice 2019 Volume Licensed1808 / 10417.20197\nOutlook 2016 MSIKB5002755; fixed build 16.0.5565.1000\n\nMicrosoft says the Click-to-Run security updates do not require a restart. The Outlook 2016 MSI update may require one. KB5002755 applies to the MSI-based edition of Outlook 2016, not the Click-to-Run edition.\nOffice 2019 and Outlook 2016 reached end of support on October 14, 2025. Microsoft nevertheless published the relevant August 2026 fixes. Organizations still operating these versions should install the released security update and maintain a supported-version migration plan; the availability of this update does not restore full product support.\n\nHow the attack path changes the response\nThe confirmed attack path begins with a malicious Office file delivered to a user and succeeds only if the user opens it. That makes email, collaboration platforms, downloads, and other file-delivery paths relevant control points, but it does not make patching optional.\nUntil every affected installation is updated, DSE recommends treating unexpected Office attachments and links to Office documents as untrusted, maintaining attachment scanning and endpoint detection controls, and prioritizing users who routinely process external documents. These are DSE operational precautions derived from the published attack path; Microsoft has not published them as a formal workaround.\n\nA practical patch-and-verify plan\n\nInventory the actual Office estate. Record product, architecture, update technology, servicing channel, and current build. Do not rely only on a generic “Office installed” result.\nPrioritize exposed workflows. Start with users and teams that frequently open documents from customers, vendors, public mailboxes, file-transfer portals, or other external sources.\nDeploy the correct release. Use the August 11 Office security update for the installed servicing channel. For MSI-based Outlook 2016, deploy KB5002755.\nVerify the installed build. Confirm the resulting version against Microsoft’s channel-specific security table. A deployment job marked successful is not proof that the intended Office build is active.\nMonitor exceptions. Track endpoints that are offline, held by update rings, failing health checks, or running end-of-support Office versions. Give every exception an owner and due date.\nInvestigate suspicious opens. If a user opened an unexpected Office file before the update, preserve the message and file metadata and review endpoint and email-security telemetry using the organization’s incident-response process.\n\nExploitation status as of August 12, 2026\nAt publication, Microsoft reported the vulnerability as not publicly disclosed, not exploited, and assessed exploitation as unlikely. CISA’s CVE enrichment records exploitation as “none,” and CVE-2026-70329 was not listed in CISA’s Known Exploited Vulnerabilities catalog when DSE checked on August 12.\nThose are dated status statements, not guarantees about future activity. The presence of an official fix, the 8.8 score, and the potential for high impact support prompt remediation even without confirmed exploitation.\n\nA note about Microsoft’s attack-vector wording\nMicrosoft’s published CVSS vector and the CVE Program record list the attack vector as Network (AV:N), and the CNA description says code execution is possible “over a network.” One sentence in Microsoft’s FAQ, however, refers to Local (AV:L). The same FAQ clearly states that the attacker sends a malicious file and the recipient must open it.\nThe most defensible description from the available source material is therefore: the malicious file can be delivered over a network, but exploitation requires the recipient to open it locally. DSE is not using the inconsistent FAQ sentence to infer a different exploit path and recommends monitoring the MSRC page for revisions.\n\nPrimary sources\n\nMicrosoft Security Response Center: CVE-2026-70329 — severity, CVSS, affected products, attack requirements, and vendor exploitation assessment.\nCVE Program record for CVE-2026-70329 — published CNA record and CISA ADP enrichment.\nMicrosoft Office security releases — August 11, 2026 fixed builds by Office servicing channel.\nMicrosoft KB5002755 for Outlook 2016 — MSI package applicability and update details.\nCISA Known Exploited Vulnerabilities Catalog — checked August 12, 2026 for current KEV status.\nMicrosoft lifecycle notice for products ending support October 14, 2025 — Office 2019 and Office 2016 lifecycle context.\n\nReviewed August 12, 2026. Vendor guidance and exploitation status can change; use the linked Microsoft advisory as the controlling source for later revisions.",
                "datePublished": "2026-08-12T15:47:15+00:00",
                "dateModified": "2026-08-12T15:47:15+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/cve-2026-70329-microsoft-outlook-rce-patch-guidance/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Person",
                    "name": "Gavin Stewart",
                    "url": "https://www.linkedin.com/in/gavin-stewart-0718/"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/cve-2026-70329-microsoft-outlook-rce-patch-guidance/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "CVE-2026-70329 in Outlook: What the 8.8 RCE Means and How to Respond"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Briefing",
                    "Important priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 1035,
                "timeRequired": "PT5M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Microsoft Security Response Center (MSRC)",
                    "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70329",
                    "datePublished": "2026-08-11"
                }
            }
        ]
    }
}