← back
CVE-2024-21413

Microsoft Outlook Remote Code Execution Vulnerability

CVSS 9.8 CRITICALEPSS 94.7%● KEVCWE-20
In short

A critical flaw in Microsoft Outlook allows attackers to execute arbitrary code on your computer by sending a specially crafted email message. This vulnerability requires no user interaction beyond opening the email and can completely compromise your system.

Technical detail

CWE-20 input validation vulnerability in Microsoft Outlook's email parsing mechanism enables unauthenticated remote code execution when processing maliciously crafted email content. The attack vector is network-based with no user privileges required; exploitation occurs during email parsing, leading to arbitrary code execution in the Outlook process context.

Summary generated and translated by AI from the official description.
Microsoft Outlook Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
public PoCs found35
githubgithub.com/xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability765githubgithub.com/CMNatic/CVE-2024-21413257githubgithub.com/duy-31/CVE-2024-21413157githubgithub.com/ThemeHackers/CVE-2024-2141325githubgithub.com/r00tb1t/CVE-2024-21413-POC17githubgithub.com/mmathivanan17/CVE-2024-2141311githubgithub.com/Mdusmandasthaheer/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability5githubgithub.com/D1se0/CVE-2024-21413-Vulnerabilidad-Outlook-LAB4githubgithub.com/ahmetkarakayaoffical/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability4githubgithub.com/X-Projetion/CVE-2024-21413-Microsoft-Outlook-RCE-Exploit2githubgithub.com/gurleen-147/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability-PoC2githubgithub.com/dshabani96/CVE-2024-214132githubgithub.com/PolarisXSec/CVE-2024-214131githubgithub.com/Redfox-Security/Unveiling-Moniker-Link-CVE-2024-21413-Navigating-the-Latest-Cybersecurity-Landscape0githubgithub.com/olebris/CVE-2024-214130githubgithub.com/ShubhamKanhere307/CVE-2024-214130githubgithub.com/ArtemCyberLab/Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-214130githubgithub.com/th3Hellion/CVE-2024-214130githubgithub.com/MQKGitHub/Moniker-Link-CVE-2024-214130githubgithub.com/yass2400012/Email-exploit-Moniker-Link-CVE-2024-21413-0githubgithub.com/KartheekKandalam99/SVPT_CW_20githubgithub.com/hau2212/Moniker-Link-CVE-2024-21413-0githubgithub.com/MSeymenD/CVE-2024-214130githubgithub.com/eylommaayan/THM---CVE-2024-21413-Moniker-Link-Microsoft-Outlook-0githubgithub.com/ViniciusFariasDev/cve-2024-21413-outlook-monikerlink-lab0githubgithub.com/dionissh/CVE-2024-214130githubgithub.com/securenetexpert/CVE-2024-21413-Moniker-Link-Writeup0githubgithub.com/SallocinAvalcante/lab-SMB-responder-CVE-2024-214130githubgithub.com/E-m-e-k-a/Moniker-Link-Lab-Setup0githubgithub.com/TheMursalin/HTB-Mailing-A-Complete-Walkthrough0githubgithub.com/pedro-lucas-melo/Estudo-de-Caso-CVE-2024-214130githubgithub.com/FathanahHidayati/https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability0githubgithub.com/bhatbhupendra/Moniker-Link--CVE-2024-21413-0githubgithub.com/KaiHaoChen04/monikerlinktest0githubgithub.com/Dhananjayasj/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability0
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →