Microsoft updated a security advisory today to warn that a critical Outlook bug was exploited in attacks as a zero-day before being fixed during this month's Patch Tuesday. Discovered by Check Point vulnerability researcher Haifei Li and tracked as CVE-2024-21413, this vulnerability leads to remote code execution (RCE) when opening emails with malicious links using a vulnerable Microsoft Outlook version. This happens because the flaw also enables attackers to bypass the Protected View (designed to block harmful content embedded in Office files by opening them in read-only mode) and open malicious Office files in editing mode. Redmond also warned that the Preview Pane is also an attack vector for this security flaw, allowing successful exploitation even when previewing maliciously crafted Office documents in Windows Explorer. Microsoft says unauthenticated attackers can exploit CVE-2024-21413 remotely in low-complexity attacks that don't require user interaction. "An attacker who successfully exploited this vulnerability could gain high privileges, which include read, write, and delete functionality," the company explains. "An attacker could craft a malicious link that bypasses the Protected View Protocol, which leads to the leaking of local NTLM credential information and remote code execution (RCE)." CVE-2024-21413 affects multiple Office products, including Microsoft Office LTSC 2021 and Microsoft 365 Apps for Enterprise, as well as Microsoft Outlook 2016 and Microsoft Off...
Microsoft: New critical Outlook RCE bug exploited as zero-day
BleepingComputer
·Sergiu Gatlan
·Published Feb 14, 2024
·Updated
Affected Software
4 affected components
Microsoft Outlook=2016
Microsoft Office=2019
Microsoft Office=LTSC 2021
Microsoft 365 Apps for Enterprise
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical remote code execution (RCE) vulnerability in Microsoft Outlook that was actively exploited as a zero-day before being patched.
2
What security implications are discussed?
The security implications include the potential for attackers to execute malicious code on vulnerable systems through the showcased Outlook bug.
3
What products or software are affected?
Affected products include Microsoft Outlook 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, and Microsoft 365 Apps for Enterprise.
4
Who discovered the vulnerability?
The vulnerability was discovered by Check Point vulnerability researcher Haifei Li.
5
When was the vulnerability patched?
The vulnerability was fixed during Microsoft's Patch Tuesday of the current month.