# CVE-2026-70329: Microsoft Outlook Remote Code Execution via Integer Overflow

> Microsoft patched CVE-2026-70329, a CVSS 8.8 integer overflow/wraparound (CWE-190) vulnerability in Outlook that allows an unauthorized attacker to execute code over a network when a victim opens a malicious Office file, typically disguised as an email attachment. Fixed in the August 2026 Patch Tuesday release; Microsoft rates exploitation as unlikely and reports no in-the-wild exploitation or public PoC.

- **Published:** 2026-08-11T00:00:00Z
- **Last reviewed:** 2026-08-11T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1991
- **ID:** TL-2026-1991
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 11 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-70329

## Description

CVE-2026-70329 is an integer overflow or wraparound weakness (CWE-190) in Microsoft Office Outlook that leads to memory corruption and remote code execution. Per the NVD description, an unauthorized attacker can execute code over a network, but exploitation requires user interaction: the victim must open a specially crafted Office file, typically delivered as an email attachment via a phishing-style lure. Cyber Security News' technical summary describes the mechanism directly: "the integer overflow bug can be triggered to corrupt memory and hijack program execution," with the resulting impact scoped to whatever privileges the logged-in victim account holds. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) confirms a network attack vector, low attack complexity, no privileges required, required user interaction, an unchanged scope, and high impact to confidentiality, integrity, and availability once the flaw is triggered.

Microsoft's own Security Update Guide FAQ clarifies terminology that is easy to misread: "the 'Remote' in the title refers to the attacker's location, not the attack vector" -- the exploit code itself executes locally on the victim's machine once the malicious file is opened (sometimes termed Arbitrary Code Execution, or ACE). MSRC's FAQ states the attack in plain terms: the attacker must "send a user a malicious Office file and convince them to open it." Notably, MSRC's own severity label for this entry is "Important" (its internal four-tier scale), while the CVSS 3.1 numeric score of 8.8 maps to the qualitative band "High" under NVD/FIRST scoring conventions -- both labels describe the same vulnerability and are not in conflict, but readers cross-referencing Microsoft's release notes against NVD should expect the naming difference. Microsoft additionally publishes a Temporal CVSS score of 7.7 (reflecting the lack of a public exploit and the 'Unlikely' exploitation rating pulling the Base 8.8 downward).

The vulnerability affects Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024 (all 32-bit and 64-bit), and standalone Microsoft Outlook 2016 (vulnerable range 16.0.0.0-16.0.5565.1000). Microsoft published the advisory and shipped fixes on August 11, 2026 as part of a Patch Tuesday release; outlets diverge on the exact total CVE count for the month (BleepingComputer reports 400 flaws/42 Critical; Cyber Security News' broader roundup reports 394; a third aggregator reports 421 including two republished non-Microsoft TPM CVEs) -- a normal artifact of different outlets snapshotting the MSRC catalog at slightly different times and applying different inclusion rules, not a discrepancy specific to this CVE. Click-to-Run editions (365 Apps for Enterprise, Office 2019/2021/2024 retail) update automatically to Version 2607 Build 20228.20190 (Current Channel) or the equivalent build for their channel; standalone Outlook 2016 MSI installations require the manually-deployed KB5002755 update, which brings the build to 16.0.5565.1000.

Microsoft credits an anonymous researcher via its Coordinated Vulnerability Disclosure (CVD) program and rates exploitation "unlikely," noting that this assessment could shift if proof-of-concept code becomes public. No PoC has been published (confirmed absent from GitHub PoC-tracking repositories as of this research pass) and the vulnerability is absent from the CISA Known Exploited Vulnerabilities (KEV) catalog as of the August 11, 2026 catalog version, consistent with Microsoft's exploitability rating. The same Patch Tuesday cycle separately fixed CVE-2026-62882 (an unrelated Outlook spoofing flaw, CVSS 4.3) and a cluster of Excel/PowerPoint/Word information-disclosure and RCE CVEs (including CVE-2026-70328, -70327, -70318, -70325, -70322, -70320, -70316, -70312, -70311, -70310, -70319, -66806); none of these is described by any reviewed source as sharing an exploitation chain or root cause with CVE-2026-70329. The month's headline zero-day was CVE-2026-68820, an actively-exploited Windows Ancillary Function Driver (AFD) elevation-of-privilege flaw (CVSS 7.0) in a driver with a recurring history of zero-days since August 2024; two sibling AFD EoP flaws in the same batch (CVE-2026-61348, CVE-2026-70307) were separately rated 'Exploitation More Likely.' Reviewed sources do not corroborate a Lazarus/FudModule attribution for CVE-2026-68820 independent of the harness's original hunt sourcing, and in any case that flaw is unconnected to the Outlook RCE documented here.

Because Microsoft did not publish a detailed technical write-up of the exploit primitive (no discussion of heap layout, ROP chains, or specific parser code paths -- standard practice for a flaw with no public PoC and an 'Unlikely' rating), and no independent researcher has published exploit analysis, the MITRE ATT&CK mapping below is intentionally bounded to what the primary sources actually state rather than the full theoretical playbook for the vulnerability class. A re-verification pass against MSRC's raw FAQ API, NVD, and Zero Day Initiative's August 2026 review confirms no additional technical detail has since surfaced: the MSRC FAQ discloses only the two lines already reflected here (an attacker must send a user a malicious Office file and convince them to open it; and the 'Remote' terminology clarification), and NVD/ZDI add no mechanism detail beyond the CVSS vector and CWE-190 classification already captured. CVE-2026-70329 should also not be confused with the unrelated, more severe CVE-2026-40361 disclosed in the same August 2026 batch: a zero-click Word rendering-engine RCE (wwlib.dll, CVSS 8.4) triggerable via Outlook's Preview Pane with no user interaction, rated 'Exploitation More Likely'. CVE-2026-70329 by contrast requires the victim to explicitly open the crafted Office file (CVSS UI:R) and remains rated 'Exploitation Unlikely'. A follow-up sourcing pass against Cyber Security News, Zero Day Initiative's write-up, the raw MSRC FAQ API, and NVD's CVE 2.0 API confirmed no further mechanism detail exists beyond what is already captured above (no macro/OLE/RTF/preview-pane specifics, no ROP-chain or heap-layout discussion, no PoC on GitHub PoC-tracking indexes). Given this evidentiary ceiling, the MITRE list below stays at 10 well-sourced techniques across 4 tactics -- expanded only with the two weaponization/delivery-channel steps MSRC's own FAQ text directly implies (obtaining, not just developing, the malicious document; and the email-sending identity required to 'send a user a malicious Office file') -- rather than padding toward a higher count with unstated post-exploitation techniques (e.g. command and control, lateral movement, or persistence) that no reviewed source attributes to this specific CVE.

## MITRE ATT&CK

- T1588.006 Obtain Capabilities: Vulnerabilities
- T1588.005 Obtain Capabilities: Exploits
- T1587.004 Develop Capabilities: Exploits
- T1587.001 Develop Capabilities: Malware
- T1588.001 Obtain Capabilities: Malware
- T1585.002 Establish Accounts: Email Accounts
- T1566.001 Phishing: Spearphishing Attachment
- T1204.002 User Execution: Malicious File
- T1203 Exploitation for Client Execution
- T1036 Masquerading

## Sources

- [Microsoft Outlook RCE Vulnerability Let Attackers Execute Malicious Code Remotely](https://cybersecuritynews.com/microsoft-outlook-rce-vulnerability-2/)
- [CVE-2026-70329 Detail](https://nvd.nist.gov/vuln/detail/CVE-2026-70329)
- [Microsoft Security Update Guide - CVE-2026-70329](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70329)
- [MSRC Security Update Guide API - CVE-2026-70329 (exploitability FAQ)](https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2026-70329)
- [CVE Record: CVE-2026-70329](https://www.cve.org/CVERecord?id=CVE-2026-70329)
- [The August 2026 Security Update Review](https://www.zerodayinitiative.com/blog/2026/8/11/the-august-2026-security-update-review)
- [Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days](https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/)
- [Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)](https://www.tenable.com/blog/microsofts-august-2026-patch-tuesday-addresses-398-cves-cve-2026-68820)
- [Microsoft Patch Tuesday - August 2026](https://www.lansweeper.com/blog/patch-tuesday/microsoft-patch-tuesday-august-2026/)
- [Microsoft Patch Tuesday Update August 2026 - 394 Vulnerabilities Fixed, Including 3 Zero-Days](https://cybersecuritynews.com/microsoft-patch-tuesday-update-august-2026/)
- [Patch Tuesday August 2026: Security Updates & CVE Analysis](https://zecurit.com/endpoint-management/patch-tuesday/)
- [Release notes for Microsoft Office security updates](https://learn.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1991
