CISA warned U.S. federal agencies on Thursday to secure their systems against ongoing attacks targeting a critical Microsoft Outlook remote code execution (RCE) vulnerability. Discovered by Check Point vulnerability researcher Haifei Li and tracked as CVE-2024-21413, the flaw is caused by improper input validation when opening emails with malicious links using vulnerable Outlook versions. The attackers gain remote code execution capabilities because the flaw lets them bypass the Protected View (which should block harmful content embedded in Office files by opening them in read-only mode) and open malicious Office files in editing mode. When it patched CVE-2024-21413 one year ago, Microsoft also warned that the Preview Pane is an attack vector, allowing successful exploitation even when previewing maliciously crafted Office documents. As Check Point explained, this security flaw (dubbed Moniker Link) lets threat actors bypass built-in Outlook protections for malicious links embedded in emails using the file:// protocol and by adding an exclamation mark to URLs pointing to attacker-controlled servers. The exclamation mark is added right after the file extension, together with random text (in their example, Check Point used "something"), as shown below: CVE-2024-21413 affects multiple Office products, including Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Outlook 2016, and Microsoft Office 2019, and successful CVE-2024-21413 attacks can result in the...
Critical RCE bug in Microsoft Outlook now exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Feb 6, 2025
·Updated
Affected Software
5 affected components
Microsoft Office LTSC=2021
Microsoft 365 Apps for Enterprise
Microsoft Outlook=2016
Microsoft Office=2019
Microsoft Outlook
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical remote code execution (RCE) vulnerability in Microsoft Outlook that is currently being exploited in attacks.
2
What security implications are discussed?
The article highlights the ongoing attacks targeting the RCE vulnerability in Microsoft Outlook, which poses significant risks to user data and system integrity.
3
What products or software are affected by the vulnerability?
The vulnerability affects Microsoft Outlook 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft 365 Apps for Enterprise.
4
What has CISA advised regarding this vulnerability?
CISA has urged U.S. federal agencies to secure their systems in response to the discovered RCE vulnerability in Microsoft Outlook.
5
Who discovered the vulnerability?
The RCE vulnerability was discovered by Check Point vulnerability researcher Haifei Li.