← voltar
CVE-2024-21413

Microsoft Outlook Remote Code Execution Vulnerability

CVSS 9.8 CRITICALEPSS 94.7%● KEVCWE-20
Em resumo

Uma falha crítica no Microsoft Outlook permite que atacantes executem código malicioso no seu computador ao enviar um email especialmente preparado. A vulnerabilidade não requer ação do usuário além de abrir o email e pode comprometer completamente seu sistema.

Detalhe técnico

Vulnerabilidade CWE-20 de validação insuficiente de entrada no mecanismo de análise de emails do Outlook permite execução remota de código não autenticada ao processar conteúdo de email malicioso. O vetor de ataque é baseado em rede sem necessidade de privilégios do usuário; a exploração ocorre durante a análise do email, resultando em execução de código arbitrário no contexto do processo Outlook.

Resumo gerado e traduzido por IA a partir da descrição oficial.
Microsoft Outlook Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
PoCs públicas encontradas35
githubgithub.com/xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability765githubgithub.com/CMNatic/CVE-2024-21413257githubgithub.com/duy-31/CVE-2024-21413157githubgithub.com/ThemeHackers/CVE-2024-2141325githubgithub.com/r00tb1t/CVE-2024-21413-POC17githubgithub.com/mmathivanan17/CVE-2024-2141311githubgithub.com/Mdusmandasthaheer/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability5githubgithub.com/D1se0/CVE-2024-21413-Vulnerabilidad-Outlook-LAB4githubgithub.com/ahmetkarakayaoffical/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability4githubgithub.com/X-Projetion/CVE-2024-21413-Microsoft-Outlook-RCE-Exploit2githubgithub.com/gurleen-147/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability-PoC2githubgithub.com/dshabani96/CVE-2024-214132githubgithub.com/PolarisXSec/CVE-2024-214131githubgithub.com/Redfox-Security/Unveiling-Moniker-Link-CVE-2024-21413-Navigating-the-Latest-Cybersecurity-Landscape0githubgithub.com/olebris/CVE-2024-214130githubgithub.com/ShubhamKanhere307/CVE-2024-214130githubgithub.com/ArtemCyberLab/Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-214130githubgithub.com/th3Hellion/CVE-2024-214130githubgithub.com/MQKGitHub/Moniker-Link-CVE-2024-214130githubgithub.com/yass2400012/Email-exploit-Moniker-Link-CVE-2024-21413-0githubgithub.com/KartheekKandalam99/SVPT_CW_20githubgithub.com/hau2212/Moniker-Link-CVE-2024-21413-0githubgithub.com/MSeymenD/CVE-2024-214130githubgithub.com/eylommaayan/THM---CVE-2024-21413-Moniker-Link-Microsoft-Outlook-0githubgithub.com/ViniciusFariasDev/cve-2024-21413-outlook-monikerlink-lab0githubgithub.com/dionissh/CVE-2024-214130githubgithub.com/securenetexpert/CVE-2024-21413-Moniker-Link-Writeup0githubgithub.com/SallocinAvalcante/lab-SMB-responder-CVE-2024-214130githubgithub.com/E-m-e-k-a/Moniker-Link-Lab-Setup0githubgithub.com/TheMursalin/HTB-Mailing-A-Complete-Walkthrough0githubgithub.com/pedro-lucas-melo/Estudo-de-Caso-CVE-2024-214130githubgithub.com/FathanahHidayati/https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability0githubgithub.com/bhatbhupendra/Moniker-Link--CVE-2024-21413-0githubgithub.com/KaiHaoChen04/monikerlinktest0githubgithub.com/Dhananjayasj/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability0
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →