New critical Microsoft Outlook RCE bug is trivial to exploit
ID: c327b0a6-7a58-58b0-8f51-d8908906504b
STIX ID: report--c327b0a6-7a58-58b0-8f51-d8908906504b
Feed Name: Bleeping Computer
A critical Outlook vulnerability (CVE-2024-21413, dubbed 'Moniker Link') lets remote unauthenticated attackers bypass Protected View and trigger remote code execution or steal NTLM credentials by using crafted file:// hyperlinks with an appended exclamation mark; the flaw affects multiple Office/Outlook versions and can be triggered via the Preview Pane. Check Point researchers disclosed the issue and Microsoft published an advisory (briefly flagging exploitation, then retracting that flag); users are advised to apply the official patch promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
