logo

Critical RCE bug in Microsoft Outlook now exploited in attacks

ID: b5488f25-8e8c-5336-9344-a80e7dc7d875

STIX ID: report--b5488f25-8e8c-5336-9344-a80e7dc7d875

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-02-06

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA warned federal agencies to urgently patch a critical Microsoft Outlook RCE vulnerability (CVE-2024-21413, "Moniker Link") that allows attackers to bypass Protected View via malicious file:// links containing an exclamation mark, potentially enabling arbitrary code execution and NTLM credential theft; Microsoft patched the issue previously, but CISA added it to its KEV catalog and required rapid remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.