Remote Code Execution Vulnerability Affects Microsoft Outlook

CVE-2024-21378
8.8HIGH

Key Information

Vendor
Microsoft
Status
Microsoft Office 2019
Microsoft 365 Apps For Enterprise
Microsoft Office Ltsc 2021
Microsoft Outlook 2016
Vendor
CVE Published:
13 February 2024

Badges

🔥 No. 1 Trending😄 Trended👾 Exploit Exists🔴 Public PoC📰 News Worthy

Summary

A remote code execution vulnerability, CVE-2024-21378, has been identified in Microsoft Outlook, with a severity of 9.8 out of 10. This vulnerability allows attackers to gain unauthorized access to Exchange servers and execute malicious code. It is actively being exploited by unknown threat actors and poses a significant risk to the confidentiality and integrity of an organization's internal email communication and data. Microsoft has released patches to mitigate the vulnerability and advises affected users to update to the latest version to prevent exploitation. The exploitation of CVE-2024-21378 could lead to unauthorized access, data breaches, system compromise, and further spread of malware.

Affected Version(s)

Microsoft Office 2019 < 19.0.0

Microsoft 365 Apps for Enterprise < 16.0.1

Microsoft Office LTSC 2021 < 16.0.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • Risk change from: 8.8 to: 8 - (HIGH)

  • Risk change from: 8 to: 8.8 - (HIGH)

  • 🔥

    Vulnerability reached the number 1 worldwide trending spot.

  • Vulnerability started trending.

  • First article discovered by NetSPI

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed1 Proof of Concept(s)5 News Article(s)
.