CVE-2024-21413

Microsoft Outlook Remote Code Execution Vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
December 08, 2023
Published Date
February 13, 2024
Last Updated
February 07, 2025
Vendor
Microsoft
Product
Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2016
Description
Microsoft Outlook Remote Code Execution Vulnerability

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2025-02-06 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2024-05-03 16:09:54 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2025-02-06 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

D1se0/CVE-2024-21413-Vulnerabilidad-Outlook-LAB

Type: github • Created: 2024-12-04 10:26:37 UTC • Stars: 2

ThemeHackers/CVE-2024-21413

Type: github • Created: 2024-08-31 13:18:43 UTC • Stars: 13

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

X-Projetion/CVE-2024-21413-Microsoft-Outlook-RCE-Exploit

Type: github • Created: 2024-05-03 16:09:54 UTC • Stars: 2

CVE-2024-21413 Microsoft Outlook RCE Exploit

dshabani96/CVE-2024-21413

Type: github • Created: 2024-02-29 10:07:34 UTC • Stars: 2

ahmetkarakayaoffical/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Type: github • Created: 2024-02-23 12:13:11 UTC • Stars: 4

Bu betik, Microsoft Outlook'ta keşfedilen ve CVSS değeri 9.8 olan önemli bir güvenlik açığı olan CVE-2024-21413 için bir kavram kanıtı (PoC) sunmaktadır. MonikerLink hatası olarak adlandırılan bu güvenlik açığı, yerel NTLM bilgilerinin potansiyel sızıntısı ve uzaktan kod çalıştırma olasılığı dahil olmak üzere geniş kapsamlı etkilere sahiptir.

Mdusmandasthaheer/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Type: github • Created: 2024-02-20 12:41:15 UTC • Stars: 6

CMNatic/CVE-2024-21413

Type: github • Created: 2024-02-17 14:52:52 UTC • Stars: 87

CVE-2024-21413 PoC for THM Lab

r00tb1t/CVE-2024-21413-POC

Type: github • Created: 2024-02-16 21:10:31 UTC • Stars: 16

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - CVE-2024-21413 POC

xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Type: github • Created: 2024-02-16 15:17:59 UTC • Stars: 726

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

duy-31/CVE-2024-21413

Type: github • Created: 2024-02-15 19:57:38 UTC • Stars: 154

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC