CVE-2013-3870: Microsoft Outlook

High severity, CVSS 9.3. EPSS: 18.6% chance of exploitation in the next 30 days.

Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nested S/MIME certificates in an e-mail message, aka "Message Certificate Vulnerability."

Affected products

  • Microsoft Outlook: version 2007 only; version 2010 only

Published 2013-09-11. Last modified 2026-06-16.