Vulnerability record · CVE-2024-21413 · published 13 February 2024
CVE-2024-21413: Microsoft Outlook improper input validation remote code execution
Microsoft · 365 Apps
CVE-2024-21413 is a critical remote code execution flaw in Microsoft Outlook caused by improper input validation, tracked publicly as the MonikerLink bug. It affects Microsoft 365 Apps, Office 2016, Office 2019 and the Office Long Term Servicing Channel, and it matters because a crafted message can trigger code execution without any user interaction beyond message handling.
Description
Microsoft Outlook Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no privileges or user interaction required, KEV listing and a 0.9466 EPSS probability make this an urgent patch-first issue.
What it is
CVE-2024-21413 is a critical remote code execution flaw in Microsoft Outlook caused by improper input validation, tracked publicly as the MonikerLink bug. It affects Microsoft 365 Apps, Office 2016, Office 2019 and the Office Long Term Servicing Channel, and it matters because a crafted message can trigger code execution without any user interaction beyond message handling.
Impact
An attacker can execute arbitrary code in the context of the victim, giving full compromise of confidentiality, integrity and availability on the affected host.
Attack surface
The flaw is network reachable (AV:N) with no privileges and no user interaction required per the CVSS vector, so delivery is through Outlook message handling rather than a local or authenticated channel. The record does not detail the exact protocol path beyond the Outlook client.
Exploitation
CISA added it to KEV on 2025-02-06 with a remediation due date of 2025-02-27, and EPSS shows a 30-day probability of 0.9466 at the 99.85th percentile, indicating active exploitation is expected or observed. A public exploit-tagged reference exists, and no ransomware campaign use is documented.
What to do
- Apply the Microsoft vendor patch from the MSRC update guide immediately on all affected Outlook and Office builds.
- If patching cannot be completed, follow CISA KEV required action and apply vendor mitigations or discontinue use of the affected product.
- Prioritize internet-facing and high-value mail users, and verify patch state across Microsoft 365 Apps, Office 2016, Office 2019 and Office LTSC.
- Restrict or block risky link and moniker handling in email where the vendor provides configuration controls.
Detection
- Hunt for Outlook processes spawning child processes such as script interpreters, cmd, powershell or mshta.
- Monitor email gateway and endpoint logs for messages containing unusual moniker or file URI style links.
- Alert on Office or Outlook crash and error telemetry correlated with inbound mail from untrusted senders.
- Review endpoint telemetry for post-exploitation behavior on hosts running unpatched Outlook builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-21413 to the Known Exploited Vulnerabilities catalog on 6 February 2025 as "Microsoft Outlook Improper Input Validation Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 27 February 2025.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-21413 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-21413), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.