CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2024-21413

CVSS 9.8v3.1pub. 2024-02-13upd. 2026-08-10

Microsoft Outlook Remote Code Execution Vulnerability

🤖 AI Analysis
How it works

The vulnerability results from improper validation of input data (CWE-20) during the processing of specially crafted MonikerLink type links in email messages. An attacker can send a victim a message containing a malicious link, which when opened or simply displayed in the preview pane can trigger code execution on the client side. The attack vector is network-based, requires no privileges or user interaction, making it exceptionally dangerous.

Impact

Successful exploitation of the vulnerability allows an attacker to execute arbitrary code remotely on the victim's computer with full impact on confidentiality, integrity, and system availability. This can lead to takeover of a workstation, theft of authentication credentials, or further lateral movement within the organization's network.

Mitigation & patch

Patches available from the vendor should be applied immediately in accordance with the Microsoft security bulletin (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413). Due to active exploitation of the vulnerability, the update should be treated as a priority. Until the patch is deployed, it is recommended to disable the message preview pane in Outlook and block suspicious links at the email gateway level.

Who is affected

Microsoft 365 Apps, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office Long Term Servicing Channel (LTSC) — exact versions indicated in vendor references (MSRC).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Microsoft 365 Apps

    APP
    Microsoft
    all versions
  • Microsoft Office 2016

    APP
    Microsoft
    all versions
  • Microsoft Office 2019

    APP
    Microsoft
    all versions
  • Microsoft Office Long Term Servicing Channel

    APP
    Microsoft
    2021

CISA KEV — detailsi

Vendori
Microsoft
Producti
Office Outlook
Added to KEVi
February 6, 2025
Remediation deadline (US Federal)i
February 27, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 27 lutego 2025
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2023-23397CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność privilege escalation w Microsoft Outlook (CVE-2023-23397)

CVE-2025-60724CRITICAL9.8PL ✓same product

Heap buffer overflow w Microsoft Graphics Component — zdalne wykonanie kodu

CVE-2023-33150CRITICAL9.6PL ✓same product

Obejście zabezpieczeń w Microsoft Office (Security Feature Bypass)

CVE-2023-21716CRITICAL9.8PL ✓same product

RCE w Microsoft Word — krytyczna podatność umożliwiająca zdalne wykonanie kodu

CVE-2020-0901CRITICAL9.8PL ✓same product

RCE w Microsoft Excel — nieprawidłowa obsługa obiektów w pamięci