Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2024-21378 — Remote Code Execution in Microsoft Outlook

Summary

NetSPI details CVE-2024-21378, authenticated RCE in Microsoft Outlook via synced form objects that sidestep the 2017 script allowlisting patch, weaponized through an updated Ruler pentesting tool.
CVE
CVE-2024-21378
Published
Collected

original ↗