logo

New Outlook Exploit Zero-Click RCE Vulnerability Exposed

ID: ebe4ef7c-7bbc-589c-868e-754857ab0091

STIX ID: report--ebe4ef7c-7bbc-589c-868e-754857ab0091

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2024-08-22

Date Updated: 2026-04-19

Author: Kaaviya

...
...

**Executive summary:** Research identified a critical Outlook vulnerability (CVE-2024-38021) that can leak local NTLM credentials and enable remote code execution by abusing composite monikers in hyperlinks; Microsoft patched related issues (including CVE-2024-21413) by blocking composite moniker parsing in some contexts, but residual attack paths remain and defenders may need virtual or additional mitigations while applying official updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.