logo

A Grim Outlook for Microsoft with MonikerLink and Exchange Vulnerabilities | UpGuard

ID: 11ac6781-c130-5e16-a0b8-b9f48202ddef

STIX ID: report--11ac6781-c130-5e16-a0b8-b9f48202ddef

Feed Name: UpGuard Blog

Threat Score
90/100

Date Published: 2024-02-21

Date Updated: 2026-05-01

...
...

Microsoft's February 2024 Patch Tuesday addresses two critical zero-day vulnerabilities—CVE-2024-21413 (MonikerLink) in Outlook, which enables unauthenticated remote code execution and can leak NTLM credentials via specially crafted moniker links, and CVE-2024-21410 in Exchange Server, a privilege escalation that can be leveraged with those leaked credentials (e.g., NTLM relay/pass-the-hash) to move laterally and exfiltrate data; both have CVSS scores of 9.8. The report lists affected Office and Exchange versions, links to vendor advisories, and recommends immediate application of Microsoft's updates, running the Exchange HealthChecker, tightening email authentication (SPF/DMARC), and validating third-party vendor patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.