ZeroHour

CVE-2024-21413

KEV PoC mass2

Improper Input Validation RCE in Microsoft Outlook (MonikerLink)

CISA: Microsoft Outlook Improper Input Validation Vulnerability

CVSS 3.1
9.8 critical
EPSS
95%p100
Published
()
KEV added
AI analysis

CVE-2024-21413 is an improper input validation flaw (CWE-20) in Microsoft Outlook, publicly dubbed "MonikerLink", in which Outlook mishandles a specially crafted hyperlink (a file:// moniker link) and bypasses the security prompt normally applied before opening such links. The flaw is triggered when a user opens or clicks a maliciously crafted link in an email, causing Outlook to invoke the target outside its protected handling. A successful attack can leak the user's NTLM credentials and can achieve remote code execution in the context of the current user; the flaw carries a critical CVSS 3.1 score of 9.8. Anyone running affected Outlook clients — Microsoft 365 Apps, Office 2016, Office 2019, and Office LTSC — is exposed, and the issue was fixed in Microsoft's February 2024 Patch Tuesday release. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-02-06, EPSS assigns a ~95% exploitation probability (100th percentile), and a public PoC is available.

What to do: Apply Microsoft's February 2024 (or later) security updates for Microsoft 365 Apps, Office 2016, Office 2019, and Office LTSC, and verify Outlook builds are current, per the KEV required action to apply vendor mitigations or discontinue use. As interim mitigation, restrict outbound SMB/NTLM from endpoints (e.g., block outbound port 445 or disable NTLM where feasible) to blunt credential leakage from crafted file:// links. Hunt for signs of exploitation, such as unexpected outbound SMB connections or NTLM authentication events following users clicking links in email.

Affected
Microsoft 365 Apps (Outlook)
microsoft Office 2016 (Outlook)all builds prior to the February 2024 security updates
microsoft Office 2019 (Outlook)all builds prior to the February 2024 security updates
microsoft Office Long Term Servicing Channel (Office LTSC, Outlook)all builds prior to the February 2024 security updates
Estimated exposure
masshundreds of millions of users — effectively every unpatched Outlook install running Microsoft 365 Apps, Office 2016/2019, or Office LTSC — Outlook is the default mail client bundled with Microsoft 365 and Office, which are deployed on hundreds of millions of enterprise and consumer devices worldwide, so exposure is limited mainly by patch status rather than configuration.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Outlook Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Office Outlook
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
365 apps, office 2016, office 2019, office long term servicing channel
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news