CVE-2024-21413 is a critical Remote Code Execution (RCE) vulnerability affecting Microsoft Outlook across various Office versions, including Microsoft 365 Apps and Office 2016/2019. With a CVSS score of 9.8, it presents a severe risk as it can be exploited remotely without user interaction, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community attention with numerous discussions and media coverage highlighting its ease of exploitation. While no public Metasploit or ExploitDB modules are available, the active exploitation and high FAUCET Risk Score of 100/100 underscore the immediate threat it poses.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_2016:-:*:*:*:-:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_2019:-:*:*:*:*:*:x86:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.