ZeroHour

CVE-2024-42220

PoC ×21
CVSS 3.1
9.1 critical
EPSS
<1%p52
Published
()
Modified
Description

A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.

Vendors
microsoft
Products
outlook
Weakness
CWE-347
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news