Remote Code Execution Vulnerability Affects Microsoft Outlook
Key Information
- Vendor
- Microsoft
- Status
- Microsoft Office 2019
- Microsoft 365 Apps For Enterprise
- Microsoft Office Ltsc 2021
- Microsoft Outlook 2016
- Vendor
- CVE Published:
- 11 June 2024
Badges
Summary
The CVE-2024-30103 vulnerability affects Microsoft Outlook, allowing attackers to run arbitrary code by sending a specially designed email, triggering the exploit upon opening. The vulnerability is concerning due to its zero-click nature, meaning it requires no user interaction, making it highly effective for attackers. A security patch has been released by Microsoft to address the issue, and organizations are advised to apply the latest updates to mitigate the risk. No known attacks exploiting the vulnerability have been reported at this time. Additionally, 50 other vulnerabilities have been addressed in Microsoft's Patch Tuesday updates for June 2024, including a critical RCE flaw in the Microsoft Message Queuing (MSMQ) service. Various other vendors have also released security updates to rectify vulnerabilities in their software.
Affected Version(s)
Microsoft Office 2019 < 19.0.0
Microsoft 365 Apps for Enterprise < 16.0.1
Microsoft Office LTSC 2021 < 16.0.1
News Articles
Technical Analysis: CVE-2024-30103
In this blog Morphisec researchers provide technical analysis of CVE-2024-30103, a remote code execution vulnerability impacting Microsoft Outlook.
3 months ago
Critical Microsoft Outlook Zero-Click RCE Flaw Executes as Email is Opened
This vulnerability, designated as CVE-2024-30103, enables attackers to run arbitrary code by sending a specially designed email. When the recipient opens the email, the exploit is triggered.
5 months ago
Microsoft Issues Patches for 51 Flaws, Including Critical MSMQ Vulnerability
Microsoft's June Patch Tuesday fixes 51 vulnerabilities, including critical flaws. Stay protected with the latest updates.
5 months ago
CVSS V3.1
Timeline
- 👾
Exploit exists.
- 🔥
Vulnerability reached the number 1 worldwide trending spot.
Vulnerability started trending.
First article discovered by Morphisec
Vulnerability published.
Vulnerability Reserved.