logo

New critical Microsoft Outlook RCE bug is trivial to exploit

ID: c327b0a6-7a58-58b0-8f51-d8908906504b

STIX ID: report--c327b0a6-7a58-58b0-8f51-d8908906504b

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-02-14

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A critical Outlook vulnerability (CVE-2024-21413, dubbed 'Moniker Link') lets remote unauthenticated attackers bypass Protected View and trigger remote code execution or steal NTLM credentials by using crafted file:// hyperlinks with an appended exclamation mark; the flaw affects multiple Office/Outlook versions and can be triggered via the Preview Pane. Check Point researchers disclosed the issue and Microsoft published an advisory (briefly flagging exploitation, then retracting that flag); users are advised to apply the official patch promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.