PT-2024-4062 · Microsoft · Outlook

Arnold Osipov

+2

·

Published

2024-06-11

·

Updated

2026-01-26

·

CVE-2024-30103

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Outlook versions prior to the fixed version
Description: A critical zero-click remote code execution vulnerability has been discovered in Microsoft Outlook. This vulnerability allows attackers to execute arbitrary code by sending a specially crafted email. The issue is related to the use of an incomplete blacklist when processing input data, which can be exploited by creating specially formed DLL files. The vulnerability can be triggered without any user interaction, simply by opening a malicious email.
Recommendations: For Microsoft Outlook versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider disabling the auto-open email feature to minimize the risk of exploitation. Restrict access to vulnerable modules to minimize the risk of exploitation. Avoid using vulnerable parameters in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

BDU:2024-04508
CVE-2024-30103

Affected Products

Outlook