CVE-2024-21402: Microsoft Outlook Elevation of Privilege Vulnerability
Published Feb 13, 2024
·Updated
Microsoft Outlook Elevation of Privilege Vulnerability
Affected Software
5 affected componentsFixes available
Microsoft 365 Apps for Enterprise
Microsoft 365 Apps for Enterprise
Microsoft 365 Apps<=2401.17231.20236
Microsoft 365 Apps for Enterprise<https://aka.ms/OfficeSecurityReleases
https://aka.ms/OfficeSecurityReleases
Microsoft 365 Apps for Enterprise<https://aka.ms/OfficeSecurityReleases
https://aka.ms/OfficeSecurityReleases
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Feb 13, 2024
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-21402?
CVE-2024-21402 is categorized as an Elevation of Privilege vulnerability affecting Microsoft Outlook.
2
Which software versions are affected by CVE-2024-21402?
CVE-2024-21402 affects Microsoft 365 Apps for Enterprise versions up to and including 2401.17231.20236.
3
How do I fix CVE-2024-21402?
To fix CVE-2024-21402, update your Microsoft 365 Apps for Enterprise to the latest security updates available.
4
What are the potential risks of CVE-2024-21402?
Exploitation of CVE-2024-21402 can allow attackers to gain elevated privileges and potentially execute arbitrary code.
5
Is CVE-2024-21402 being actively exploited?
As of now, there is no public information confirming active exploitation of CVE-2024-21402.