Microsoft Outlook Remote Code Execution Vulnerability
The vulnerability results from improper validation of input data (CWE-20) during the processing of specially crafted MonikerLink type links in email messages. An attacker can send a victim a message containing a malicious link, which when opened or simply displayed in the preview pane can trigger code execution on the client side. The attack vector is network-based, requires no privileges or user interaction, making it exceptionally dangerous.
Successful exploitation of the vulnerability allows an attacker to execute arbitrary code remotely on the victim's computer with full impact on confidentiality, integrity, and system availability. This can lead to takeover of a workstation, theft of authentication credentials, or further lateral movement within the organization's network.
Patches available from the vendor should be applied immediately in accordance with the Microsoft security bulletin (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413). Due to active exploitation of the vulnerability, the update should be treated as a priority. Until the patch is deployed, it is recommended to disable the message preview pane in Outlook and block suspicious links at the email gateway level.
Microsoft 365 Apps, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office Long Term Servicing Channel (LTSC) — exact versions indicated in vendor references (MSRC).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMicrosoft 365 Apps
APPMicrosoftall versionsMicrosoft Office 2016
APPMicrosoftall versionsMicrosoft Office 2019
APPMicrosoftall versionsMicrosoft Office Long Term Servicing Channel
APPMicrosoft2021
CISA KEV — detailsi
- Vendori
- Microsoft ↗
- Producti
- Office Outlook
- Added to KEVi
- February 6, 2025
- Remediation deadline (US Federal)i
- February 27, 2025(overdue)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.
Related vulnerabilities
Krytyczna podatność privilege escalation w Microsoft Outlook (CVE-2023-23397)
Heap buffer overflow w Microsoft Graphics Component — zdalne wykonanie kodu
Obejście zabezpieczeń w Microsoft Office (Security Feature Bypass)
RCE w Microsoft Word — krytyczna podatność umożliwiająca zdalne wykonanie kodu
RCE w Microsoft Excel — nieprawidłowa obsługa obiektów w pamięci