The US Government warns users to patch this critical Microsoft Outlook -Error


  • CISA adds an Outlook incorrect entry validation error to KEV
  • Deadline for Patch is February 27, 2025
  • Criminals use it for the execution of remote code

The US Cyber ​​Security and Infrastructure Security Agency (CISA) has added a 2024 Outlook error to its catalog of known vulnerabilities, warned users of misuse of wild and give federal agencies three weeks (until February 27) to patch up or stop using The tool completely.

CVE-2024-21413 is a wrong input validation error that plagues Microsoft Outlook. It was discovered in 2024 by Check Point’s researcher Haifei Li, and got a severity of 9.8/10 (critical). Cyber ​​criminals could create special E -mail messages, filled with a particular type of hyperlink that would allow them to run arbitrary code externally. By utilizing this vulnerability, attackers can bypass Outlook’s protected view (a feature designed to open potentially harmful files in read -only mode) and instead open malicious files in editing mode.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top