← Vulnerability feed

Vulnerability record · CVE-2024-21413 · published 13 February 2024

CVE-2024-21413: Microsoft Outlook improper input validation remote code execution

Microsoft · 365 Apps

CVE-2024-21413 is a critical remote code execution flaw in Microsoft Outlook caused by improper input validation, tracked publicly as the MonikerLink bug. It affects Microsoft 365 Apps, Office 2016, Office 2019 and the Office Long Term Servicing Channel, and it matters because a crafted message can trigger code execution without any user interaction beyond message handling.

9.8 CVSS 3.1 Critical CISA KEV since 6 Feb 2025 EPSS 95% · top 0.1% CWE-20 · Improper input validation
9.8CVSS 3.1 base score
95%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
6References, 1 tagged exploit
10 Aug 2026Last modified by NVD

Description

Microsoft Outlook Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no privileges or user interaction required, KEV listing and a 0.9466 EPSS probability make this an urgent patch-first issue.

What it is

CVE-2024-21413 is a critical remote code execution flaw in Microsoft Outlook caused by improper input validation, tracked publicly as the MonikerLink bug. It affects Microsoft 365 Apps, Office 2016, Office 2019 and the Office Long Term Servicing Channel, and it matters because a crafted message can trigger code execution without any user interaction beyond message handling.

Impact

An attacker can execute arbitrary code in the context of the victim, giving full compromise of confidentiality, integrity and availability on the affected host.

Attack surface

The flaw is network reachable (AV:N) with no privileges and no user interaction required per the CVSS vector, so delivery is through Outlook message handling rather than a local or authenticated channel. The record does not detail the exact protocol path beyond the Outlook client.

Exploitation

CISA added it to KEV on 2025-02-06 with a remediation due date of 2025-02-27, and EPSS shows a 30-day probability of 0.9466 at the 99.85th percentile, indicating active exploitation is expected or observed. A public exploit-tagged reference exists, and no ransomware campaign use is documented.

What to do

  • Apply the Microsoft vendor patch from the MSRC update guide immediately on all affected Outlook and Office builds.
  • If patching cannot be completed, follow CISA KEV required action and apply vendor mitigations or discontinue use of the affected product.
  • Prioritize internet-facing and high-value mail users, and verify patch state across Microsoft 365 Apps, Office 2016, Office 2019 and Office LTSC.
  • Restrict or block risky link and moniker handling in email where the vendor provides configuration controls.

Detection

  • Hunt for Outlook processes spawning child processes such as script interpreters, cmd, powershell or mshta.
  • Monitor email gateway and endpoint logs for messages containing unusual moniker or file URI style links.
  • Alert on Office or Outlook crash and error telemetry correlated with inbound mail from untrusted senders.
  • Review endpoint telemetry for post-exploitation behavior on hosts running unpatched Outlook builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-21413 to the Known Exploited Vulnerabilities catalog on 6 February 2025 as "Microsoft Outlook Improper Input Validation Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 27 February 2025.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-21413 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2024-38189Microsoft Project Remote Code Execution via Improper Input ValidationMicrosoft Project and related Office products contain a remote code execution flaw rooted in improper input validation. An attacker can trigger code …KEVEPSS 8.2%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed7.8CVE-2026-21514Microsoft Word security feature bypass via untrusted inputMicrosoft Word relies on untrusted inputs when making a security decision, allowing an attacker to bypass a security feature. The flaw affects Micros…KEVEPSS 1.5%analysed7.8CVE-2026-21509Microsoft Office untrusted input security feature bypassMicrosoft Office relies on untrusted inputs when making a security decision, letting an unauthorized attacker bypass a security feature locally. The …KEVEPSS 71%analysed7.8CVE-2021-42292Microsoft Excel security feature bypass via crafted fileCVE-2021-42292 is a security feature bypass in Microsoft Excel and related Office products. The record gives only a one-line description, so the exac…KEVEPSS 43%analysed7.8CVE-2021-38646Microsoft Office Access Connectivity Engine remote code executionThe Microsoft Office Access Connectivity Engine contains a remote code execution flaw. The record gives no root-cause detail beyond the CWE being mar…KEVEPSS 8.0%analysed7.6CVE-2021-27059Microsoft Office remote code execution flawCVE-2021-27059 is a remote code execution vulnerability in Microsoft Office and Office 2016. The record gives only the generic title and no root-caus…KEVEPSS 6.1%analysed

Source: NIST National Vulnerability Database (record CVE-2024-21413), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.