EIP-2026-115753

PRE-CVE

Microsoft Outlook - HTML Email Denial of Service

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115753. PoCs published by Haifei Li.

AI-analyzed exploit summary This is a technical writeup detailing a DoS vulnerability in Microsoft Outlook caused by a malformed HTML email with specific CSS. The crash occurs due to a null pointer dereference in the `wwlib!DllGetLCID` module during CSS rendering.

Description

Microsoft Outlook - HTML Email Denial of Service

Exploits (1)

exploitdb WRITEUP
by Haifei Li · textdoswindows
https://www.exploit-db.com/exploits/41756

This is a technical writeup detailing a DoS vulnerability in Microsoft Outlook caused by a malformed HTML email with specific CSS. The crash occurs due to a null pointer dereference in the `wwlib!DllGetLCID` module during CSS rendering.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Outlook (tested on Office 2010 14.0.7177.5000)
No auth needed
Prerequisites: Ability to send an email to the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026