logo

PoC Exploit Released for Critical Outlook 0-Click Remote Code Execution Vulnerability

ID: 93898984-e612-5a31-bf52-26b11a58c264

STIX ID: report--93898984-e612-5a31-bf52-26b11a58c264

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-12-01

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Executive summary:** A critical Outlook RCE (CVE-2024-21413, "MonikerLink") with CVSS 9.8 has a public Python PoC demonstrating how specially crafted file:// links can bypass Protected View, trigger SMB connections that leak NTLM credentials, and enable remote code execution; defenders should apply Microsoft patches, monitor for the file:\\ pattern (YARA rule), and consider blocking outbound SMB (port 445).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.