Remote Code Execution Vulnerability Affects Microsoft Outlook
Key Information
- Vendor
- Microsoft
- Status
- Microsoft Office 2019
- Microsoft 365 Apps For Enterprise
- Microsoft Office Ltsc 2021
- Microsoft Outlook 2016
- Vendor
- CVE Published:
- 13 February 2024
Badges
Summary
A remote code execution vulnerability, CVE-2024-21378, has been identified in Microsoft Outlook, with a severity of 9.8 out of 10. This vulnerability allows attackers to gain unauthorized access to Exchange servers and execute malicious code. It is actively being exploited by unknown threat actors and poses a significant risk to the confidentiality and integrity of an organization's internal email communication and data. Microsoft has released patches to mitigate the vulnerability and advises affected users to update to the latest version to prevent exploitation. The exploitation of CVE-2024-21378 could lead to unauthorized access, data breaches, system compromise, and further spread of malware.
Affected Version(s)
Microsoft Office 2019 < 19.0.0
Microsoft 365 Apps for Enterprise < 16.0.1
Microsoft Office LTSC 2021 < 16.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Positive Technologies перечислила трендовые уязвимости прошедшего марта
Эксперты Positive Technologies отнесли к трендовым уязвимостям марта пять проблем, обнаруженных в продуктах Fortinet, JetBrains и Microsoft. К трендовым относятся уязвимости уже использовавшиеся в атаках и те, эксплуатация которых прогнозируется в ближайшее время.
7 months ago
CVE-2024-21378 Detection: Vulnerability in Microsoft Outlook Leads to Authenticated Remote Code Execution - SOC Prime
Detect CVE-2024-21378 exploitation attempts resulting in Microsoft Outlook remote code execution with detection rules from SOC Prime.
8 months ago
Microsoft Outlook RCE vulnerability CVE-2024-21378; patched in February 2024
[German]On February 13, 2024, the remote code execution vulnerability CVE-2024-21378 in Microsoft Outlook was also closed with the security updates. As of March 11, 2024, an in-depth analysis of the vulnerability has now been published, as I saw in a tweet yesterday. Outlook RCE vulnerability C
8 months ago
CVSS V3.1
Timeline
- 👾
Exploit exists.
Risk change from: 8.8 to: 8 - (HIGH)
Risk change from: 8 to: 8.8 - (HIGH)
- 🔥
Vulnerability reached the number 1 worldwide trending spot.
Vulnerability started trending.
First article discovered by NetSPI
Vulnerability published.
Vulnerability Reserved.