CVE-2014-5239: Microsoft Outlook.com

Medium severity, CVSS 4.0. EPSS: 2.9% chance of exploitation in the next 30 days.

The Microsoft Outlook.com application before 7.8.2.12.49.7090 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Affected products

  • Microsoft Outlook.com: up to and including 7.8.2.12.49.6434; version 7.8.2.10.47.7365 only; version 7.8.2.11.48.4848 only; version 7.8.2.12.49.0430 only; version 7.8.2.12.49.5701 only

Published 2014-08-14. Last modified 2026-06-17.