Programmatically grab outlook credentials to send arbitrary mail

I'm approaching security as I recently changed my job and now I'm a systemAdmin. I have a doubt regarding the protection of a network, more precisely, the protection of my data. Let's suppose I have a network protected by a firewall to stop all connections, in and out, BUT email service (which is 143 and 25 ports to a particular server); let's also suppose that the clients are using outlook. Do you think that a malicious software can send mail to communicate something (of course with attachments) without the user permission and hidden by the user activity? My question is based on the fact tha

