Security
Loading…

CVE-2024-21413

CRITICALCVSS 9.8Known Exploited
Description

Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.

Timeline
Published:February 13th, 2024 6:16 PM
Last modified:August 10th, 2026 4:18 PM
Added to KEV:February 6th, 2025
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

microsoft

Products

365_appsoffice_2016office_2019office_long_term_servicing_channel
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute