Outlook Users Beware 0-Day Exploit Released On Hacking Forums

Outlook has identified a security flaw that affects how it handles certain hyperlinks. 

Malware actors actively exploit the vulnerability in real-world attacks.

The assigned CVE number for this vulnerability is CVE-2024-21413, with a severity rating of 9.8 (Critical).

Microsoft has successfully resolved the vulnerability in question and implemented the fix in their February 2024 Patch Tuesday release.

In case of successful exploitation of the vulnerability, a malicious actor can bypass the protected view of Office and open a file in editing mode instead of the protected mode.

Outlook 0-Day RCE Flaw

According to the Checkpoint report, if the hyperlink starts with http:// or https://, Outlook uses Windows’s default browser to open the URL.

If there are additional protocols, such as the “Skype” URL protocol, clicking on the hyperlink will trigger a security warning.

In other cases, like the “file://” protocol, Outlook did not display a warning dialog box.

A slight modification in the “file://” protocol link bypasses the previously shown security restriction and proceeds to access the resource.

According to experts, utilizing this particular resource involves utilizing the SMB protocol.

However, this protocol has a flaw where it inadvertently reveals the local NTLM credentials during the access process.

Exploit on Hacking Forums

The Daily Dark Web recently reported that specific hacking forums have been discussing an exploit for CVE-2024-21413.

This exploit allows attackers to access NTLM information and execute remote code.

The vulnerability can exploit the Office Protected View and use it as a means of attack to target other Office applications.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are extremely harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer overflow…

33 minutes ago

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing attackers…

40 minutes ago

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a cyberattack…

45 minutes ago

ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials

The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens, has…

50 minutes ago

Nagios XI Flaw Exposes User Details and Emails to Unauthenticated Attackers”

A security vulnerability in Nagios XI 2024R1.2.2, tracked as CVE-2024-54961, has been disclosed, allowing unauthenticated…

4 hours ago

Critical UniFi Protect Camera Vulnerability Enables Remote Code Execution Attacks

Ubiquiti Networks has issued an urgent security advisory (Bulletin 046) warning of multiple critical vulnerabilities…

4 hours ago