CVE-2024-21413General(microsoft / 365_apps)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft 365_apps systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Outlook Remote Code Execution Vulnerability

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-02-27. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-20

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • office_2016
  • office_2019
  • office_long_term_servicing_channel

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 57 mentions across 43 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 22 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 38 signals
  • General: 23 classified signals
  • Disclosure: 6 classified signals
  • Peaked 5d ago at 3 mentions (2026-08-07); latest day: 1
  • 57 total mentions across 43 days

Affected systems

Vendors
Products
365_appsoffice_2016office_2019office_long_term_servicing_channel

2 versions affected across 4 products

Deep dive

Activity timeline57 mentions / 43d
01223Mentions · 2026-01-28: 1Mentions · 2026-01-30: 1Mentions · 2026-01-31: 1Mentions · 2026-02-02: 2Mentions · 2026-02-03: 2Mentions · 2026-02-05: 2Mentions · 2026-02-06: 1Mentions · 2026-02-08: 1Mentions · 2026-02-13: 1Mentions · 2026-02-15: 1Mentions · 2026-02-19: 2Mentions · 2026-02-20: 2Mentions · 2026-02-26: 2Mentions · 2026-02-28: 2Mentions · 2026-03-08: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-14: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 2Mentions · 2026-03-18: 1Mentions · 2026-03-25: 1Mentions · 2026-04-02: 1Mentions · 2026-04-06: 1Mentions · 2026-04-10: 1Mentions · 2026-04-17: 1Mentions · 2026-04-20: 1Mentions · 2026-04-22: 1Mentions · 2026-05-04: 2Mentions · 2026-05-06: 1Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Mentions · 2026-06-18: 1Mentions · 2026-06-24: 1Mentions · 2026-07-03: 1Mentions · 2026-07-26: 1Mentions · 2026-07-28: 1Mentions · 2026-08-07: 3Mentions · 2026-08-23: 1Mentions · 2026-09-05: 1Mentions · 2026-09-14: 2Mentions · 2026-09-23: 3Mentions · 2026-09-24: 1PoC Mentioned / Linked · 2026-01-31: 1PoC Mentioned / Linked · 2026-02-05: 1PoC Mentioned / Linked · 2026-02-06: 1PoC Mentioned / Linked · 2026-02-08: 1PoC Mentioned / Linked · 2026-02-13: 1PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-02-20: 1PoC Mentioned / Linked · 2026-02-26: 1PoC Mentioned / Linked · 2026-02-28: 1PoC Mentioned / Linked · 2026-03-10: 1PoC Mentioned / Linked · 2026-03-16: 1PoC Mentioned / Linked · 2026-03-17: 1PoC Mentioned / Linked · 2026-04-22: 1PoC Mentioned / Linked · 2026-05-04: 1PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-06-18: 1PoC Mentioned / Linked · 2026-08-07: 2PoC Mentioned / Linked · 2026-08-23: 1PoC Mentioned / Linked · 2026-09-14: 1PoC Mentioned / Linked · 2026-09-23: 1PoC Mentioned / Linked · 2026-09-24: 1Exploit Tool / Code · 2026-03-17: 1Exploit Tool / Code · 2026-08-07: 2Exploit Tool / Code · 2026-09-23: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-05-04: 2Active Exploitation · 2026-07-28: 1Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-07-28: 1Technical Details · 2026-01-28: 1Technical Details · 2026-02-02: 2Technical Details · 2026-02-03: 2Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-13: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 2Technical Details · 2026-02-26: 2Technical Details · 2026-02-28: 2Technical Details · 2026-03-11: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 2Technical Details · 2026-03-18: 1Technical Details · 2026-03-25: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-20: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-08: 1Technical Details · 2026-06-18: 1Technical Details · 2026-06-24: 1Technical Details · 2026-07-26: 1Technical Details · 2026-07-28: 1Technical Details · 2026-08-23: 1Technical Details · 2026-09-05: 1Technical Details · 2026-09-14: 201-2802-0302-1302-2603-1103-1804-1005-0406-1807-2809-1409-24
Signal classification6 categories
General
2340.4%
PoC
2035.1%
Disclosure
610.5%
Active Exploitation
47.0%
Exploit
35.3%
Patch
11.8%
Referenced assets38 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-281
General1
2026-01-301
General1
2026-01-311
PoC1
2026-02-022
Disclosure1General1
2026-02-032
Disclosure2
2026-02-052
General2
2026-02-061
PoC1
2026-02-081
PoC1
2026-02-131
PoC1
2026-02-151
General1
2026-02-192
General1PoC1
2026-02-202
Disclosure1PoC1
2026-02-262
PoC2
2026-02-282
General1PoC1
2026-03-081
General1
2026-03-101
PoC1
2026-03-111
General1
2026-03-141
General1
2026-03-161
PoC1
2026-03-172
Active Exploitation1PoC1
2026-03-181
Disclosure1
2026-03-251
General1
2026-04-021
Patch1
2026-04-061
PoC1
2026-04-101
General1
2026-04-171
General1
2026-04-201
Exploit1
2026-04-221
PoC1
2026-05-042
Active Exploitation2
2026-05-061
General1
2026-05-081
PoC1
2026-05-091
General1
2026-06-181
PoC1
2026-06-241
General1
2026-07-031
General1
2026-07-261
General1
2026-07-281
Active Exploitation1
2026-08-073
Exploit2General1
2026-08-231
PoC1
2026-09-051
General1
2026-09-142
Disclosure1PoC1
2026-09-233
General2PoC1
2026-09-241
PoC1
Full discourse20 posts
  • RabiX Security@rabixSecurity
    General

    🔍 SploitScan: Investigating CVE-2024-21413 A quick demo using SploitScan to retrieve vulnerability and publicly available exploit information for a specific CVE. 💻🛡️ GitHub Educational & defensive security research only #SploitScan #CVE #CyberSecurity #InfoSec https://t.co/lieyiCnfbj

    Post summary

    The text introduces SploitScan as a tool for retrieving vulnerability/exploit data for CVE-2024-21413 during educational research but lacks explicit confirmation of PoC links, active exploitation, or technical details.

    1170124684.4K
    2.1K followersView on X
  • Oge_chee@Ogechee_
    General

    I started the exploitation basics module on THM! (CVE-2024-21413) covers a vulnerability in Outlook that allowed attackers to bypass security by adding "!" to a file:// link in an email. Once clicked, it could steal your NTLM credentials. Metasploit is a powerful tool that facilitates the exploitation process. #Cybersecurity #LearningInPublic

    Post summary

    The post outlines how CVE‑2024‑21413 enables NTLM credential theft via a crafted Outlook link, but it provides no proof of concept, exploit code, active usage, or patch information.

    3607172.3K
    1.3K followersView on X
  • Mahmoud@M4HCyber
    General

    Two rooms completed on TryHackMe 🔥 ✅ John the Ripper: The Basics ✅ Moniker Link CVE-2024-21413 #Cybersecurity #TryHackMe #JohnTheRipper #180DaysOfCybersecurity https://t.co/0xRFpBqMIs

    Post summary

    The tweet references a TryHackMe room related to CVE-2024-21413 but offers no technical, exploit, or mitigation details.

    111110685
    942 followersView on X
  • Dh💎rkaz@peachnez28
    General

    Day 67: Road to being a Cybersecurity Analyst🛡️ I completed the Moniker Link (CVE-2024-21413) room on THM. It was a hassle trying to get the responder to listen but i finally figured it out. Cc: @segoslavia #CyberSec https://t.co/jXcugODBnI

    Post summary

    The user reports completing a training room (Moniker Link) on THM related to CVE‑2024‑21413, without providing any exploit details or patch information.

    11170903
    1.0K followersView on X
  • DGilcore@DGilcore
    PoC

    I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! An Outlook's vulnerability in 2024 that leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://tryhackme.com/room/monikerlink?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=652b80dc816dcb3e8c5b4b23 #tryhackme via @tryhackme @ireteeh @Adanna_techie @AdePelumi15 https://t.co/11FdaNiKwk

    Post summary

    The tweet announces the completion of a TryHackMe training room that demonstrates how CVE‑2024‑21413 can be used to leak user credentials by bypassing Outlook’s Protected View, highlighting the existence of a proof‑of‑concept.

    1102197
    38 followersView on X
  • joseph@jeo_crypts
    Disclosure

    Happy new month 🎉 February is here and the grind continues. Wrapped up the Moniker Link module (CVE-2024-21413). Learned how Outlook can leak NTLM hashes via Moniker Links and how to defend against it. #Cybersecurity #LearningInPublic #TechJourney https://t.co/aYMQMi4qlx

    Post summary

    The text discloses that CVE‑2024‑21413 allows Outlook to leak NTLM hashes through Moniker Links and describes defensive measures.

    1103096
    50 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-6VzYuGW ( CVE-2025-32432 ) EGE-GH-xiVZBJy ( CVE-2026-0092 ) EGE-GH-eHNcyov ( CVE-2024-21413 ) EGE-GH-9UtrTVp ( CVE-2024-21413 ) EGE-GH-Ix6VGxH ( CVE-2023-6553 ) ..🧵👇

    Post summary

    The post lists several CVEs labeled as critical but offers no additional details on exploitation, patches, or technical nature.

    20011173
    365 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2025-6325, CVE-2025-6327 CVE-2024-21413 CVE-2026-14894 CVE-2026-90817 CVE-2026-90817 ..🧵👇

    Post summary

    The tweet acts as a daily threat digest, enumerating several CVEs as critical exploits disclosed today without providing proof‑of‑concept code, exploit tools, patches, or evidence of active exploitation.

    1101055
    227 followersView on X
  • oluwa joba 😊@uglyoluwajoba
    General

    🔐 Another milestone unlocked! Completed the Moniker Link (CVE-2024-21413) room on TryHackMe. Learned how a malicious hyperlink can bypass Outlook’s Protected View and potentially expose authentication hashes. One lab closer to becoming job-ready. 🚀 #Cybersecurity #TryHackMe https://t.co/p3OMTRJWT0

    Post summary

    The user completed a TryHackMe lab focused on CVE‑2024‑21413, learning that a malicious hyperlink can bypass Outlook’s Protected View and potentially expose authentication hashes. No code, active exploitation, or patch information was provided.

    0111097
    37 followersView on X
  • Saaram@saaramhussnain
    General

    I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! https://t.co/igg97EGdwm

    Post summary

    The tweet announces completion of a TryHackMe challenge for CVE‑2024‑21413 and provides a link to the room, but offers no additional details on exploitation, mitigation, or technical specifics.

    0003095
    13 followersView on X
  • GoCocoaAI@GoCocoaAI
    General

    Sources for the three publicly verified CVEs in this brief: CVE-2024-3094 (XZ Utils / liblzma supply-chain backdoor, CVSS 10.0): https://nvd.nist.gov/vuln/detail/CVE-2024-3094 CVE-2024-1709 (ConnectWise ScreenConnect auth bypass, CVSS 10.0): https://nvd.nist.gov/vuln/detail/CVE-2024-1709 CVE-2024-27198 (JetBrains TeamCity auth bypass, CVSS 9.8): https://nvd.nist.gov/vuln/detail/CVE-2024-27198 Exploitation forecast data, HMM lifecycle posteriors, and aggregate panel signal via AEGIS at 23:46 UTC 2026-06-24. CVE-2024-21413 and CVE-2024-23897 NVD entries available at http://nvd.nist.gov; omitted from allowed URL set for this brief.

    Post summary

    The brief simply enumerates three publicly verified CVEs with brief technical details and NVD links, without any information about PoCs, exploit tools, active use, patches, or false positives.

    0002097
    35 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    💀 CRITICAL Exploits Trending ├ CVE-2025-6325 / CVE-2025-6327 · PoC live ├ CVE-2024-21413 — "MonikerLink" · PoC live └ CVE-2026-14894 · CVE-2026-90817 · PoC live

    Post summary

    The post focuses on multiple CVEs and explicitly states that PoCs are live, making PoC availability the main takeaway. No patch, active-exploitation evidence, or specific exploit tooling is provided.

    1000039
    308 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] CVE-2024-21413 [CRITICAL/PoC] monikerlink-cve-2024-21413-writeup 🔗 https://exploitgrid.net/exploits/8fc82742-b01f-4bed-8db0-360cb81bf967

    Post summary

    The tweet announces a proof-of-concept (PoC) for CVE-2024-21413, linking to an exploit writeup, and labels it as critical. It focuses on the existence of a PoC rather than detailing active exploitation, patches, or technical specifics.

    1000031
    227 followersView on X
  • Ogunleye Oluwasemilore@Ogunley68617855
    Disclosure

    What I Learned: What’s CVE-2024-21413? Exploits a bug in how Outlook handles file:// and http:// links in specially crafted .RTF files Bypasses Protected View in Outlook Leads to NTLM hash leaks via UNC paths

    Post summary

    The text describes CVE-2024-21413 as an Outlook vulnerability involving malicious RTF files that bypass Protected View and leak NTLM hashes via UNC paths, providing technical details without mentioning PoC, exploits, or patches.

    1000046
    12 followersView on X
  • Ogunleye Oluwasemilore@Ogunley68617855
    PoC

    I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://tryhackme.com/room/monikerlink?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=6800564c82ba819152df5383 #tryhackme via @tryhackme

    Post summary

    The text describes using CVE-2024-21413 in a TryHackMe room to bypass Outlook's Protected View and leak credentials, implying a Proof of Concept is provided through the room's guided exploitation.

    1000043
    12 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-9UtrTVp [CRITICAL/PoC] Linked: CVE-2024-21413 tryhackme-monikerlink-writeup 🔗 https://exploitgrid.net/exploits/2ab20b9d-b203-4fa9-afbd-d9193695407c

    Post summary

    The post announces CVE‑2024‑21413 as a critical vulnerability with an available proof of concept and functional exploit code, but makes no claim of active exploitation or vendor fixes.

    1000042
    29 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-eHNcyov [CRITICAL/PoC] Linked: CVE-2024-21413 CVE-2024-21413-Microsoft-Outlook-Moniker-Link-Vulnerability 🔗 https://exploitgrid.net/exploits/41def532-cb1a-4f3d-9999-ce3af7caa702

    Post summary

    The post announces a PoC and functional exploit for CVE‑2024‑21413, a Microsoft Outlook moniker link vulnerability, via an exploit grid link, but provides no evidence of active exploitation or patch information.

    1000042
    29 followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    Microsoft's Outlook zero-day CVE-2024-21413 is being actively weaponized. The RCE bypasses authentication—this isn't theoretical anymore. Patching is step one, but monitoring your email gateways for anomalous attachment execution is non-negotiable right now.

    Post summary

    Microsoft’s Outlook CVE‑2024‑21413 is being actively exploited with an RCE that bypasses authentication; patching and monitoring of email gateways are urgently recommended.

    00010155
    481 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-21413. Status: ✅ Confirmed exploited in the wild Date added: 2025-02-06 Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Post summary

    CVE-2024-21413 has been confirmed exploited in the wild; users should apply vendor mitigations or discontinue use.

    1000051
    152 followersView on X
  • rickert155@rickert155
    General

    I just completed Moniker Link (CVE-2024-21413) room on TryHackMe! Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View. https://tryhackme.com/room/monikerlink?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=699c69173e88c997a806a8a3 #tryhackme через @tryhackme

    Post summary

    The tweet announces a TryHackMe room demonstrating credential leakage via CVE‑2024‑21413 to bypass Outlook’s Protected View, but it does not include explicit PoC code, exploit details, or vendor remediation information.

    00100110
    11 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps---
Appmicrosoftoffice_2016--x64
Appmicrosoftoffice_2016--x86
Appmicrosoftoffice_2019--x64
Appmicrosoftoffice_2019--x86
Appmicrosoftoffice_long_term_servicing_channel2021--

Explore more