HomeSecurityCritical Microsoft Outlook vulnerability used in attacks

Critical Microsoft Outlook vulnerability being exploited in attacks

CISA has warned US federal agencies to secure their systems against a critical Microsoft Outlook vulnerability that allows remote code execution (RCE) and is now being used in attacks.

Microsoft Outlook vulnerability

The vulnerability is tracked as CVE-2024-21413 and was discovered by Check Point researcher Haifei Li . It is caused by improper login validation when opening emails with malicious links. This occurs in vulnerable versions of Outlook.

The vulnerability could allow attackers to gain remote code execution by bypassing Protected View, which normally blocks malicious content embedded in Office files by opening them in read-only mode. The vulnerability allows malicious Office files to open in edit mode.

See also: Multiple vulnerabilities in Cisco SNMP allow DoS attacks

The vulnerability in question has been fixed for a year. However, those who have not applied the updates are at risk!

As Check Point explained, the vulnerability allows attackers to bypass Outlook's built-in protections for malicious linksembedded in emails by using the file:// protocol and adding an exclamation mark to URLs that point to servers controlled by the attackers. The exclamation mark is added immediately after the file extension, along with random text.

The Outlook vulnerability affects multiple Office products, including Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Outlook 2016, and Microsoft Office 2019.

See also: CISA added Linux kernel vulnerability to KEV List

Critical Microsoft Outlook vulnerability being exploited in attacks

A successful attack could lead to stolen NTLM credentials and code execution via malicious Office documents.

On Thursday, CISA added the vulnerability to its list of Known Exploitable Vulnerabilities (KEVs). Federal agencies must secure their networks by February 27.

While CISA's KEV list is primarily designed to alert federal agencies, all organizations should prioritize patching this vulnerability.

The list is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.

See also: Netgear fixed two critical vulnerabilities in many WiFi routers

Overall, CISA is a great help in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, governments , and local authorities, to improve the security of digital systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: www.bleepingcomputer.com


📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS