PoC Exploit Released for Critical Outlook 0-Click Remote Code Execution Vulnerability
ID: 93898984-e612-5a31-bf52-26b11a58c264
STIX ID: report--93898984-e612-5a31-bf52-26b11a58c264
Feed Name: cybersecurityNews.com
Threat Score
**Executive summary:** A critical Outlook RCE (CVE-2024-21413, "MonikerLink") with CVSS 9.8 has a public Python PoC demonstrating how specially crafted file:// links can bypass Protected View, trigger SMB connections that leak NTLM credentials, and enable remote code execution; defenders should apply Microsoft patches, monitor for the file:\\ pattern (YARA rule), and consider blocking outbound SMB (port 445).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
