PT-2024-6169 · Microsoft · Outlook
Francesco Benvenuto
·
Published
2024-04-16
·
Updated
2025-08-22
·
CVE-2024-42220
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook version 16.83.3 for macOS
Description
The issue is related to a library injection vulnerability in Microsoft Outlook for macOS. This vulnerability allows a specially crafted library to leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability, making use of the vulnerable application's permissions. The vulnerability is associated with errors in cryptographic signature verification. It has been reported that this issue is being actively exploited.
Recommendations
For Microsoft Outlook version 16.83.3 for macOS, consider disabling the use of external libraries until a patch is available to prevent potential exploitation. Restrict access to the vulnerable library injection mechanism to minimize the risk of permission bypass. Avoid using the application with elevated privileges until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Outlook