Microsoft Outlook Vulnerability CVE-2024-38173 Exposed: Remote Code Execution Risk Revealed

Date:

Updated: [falahcoin_post_modified_date]

Security researchers have revealed a significant vulnerability in Microsoft Outlook. According to Morphisec Threat Labs, which discovered the flaw, CVE-2024-38173 is a Form Injection Remote Code Execution (RCE) vulnerability with a CVSS score of 6.7.

It is similar to CVE-2024-30103, which was patched in July 2024. The vulnerability CVE-2024-38173 is characterized by the weakness CWE-73: External Control of File Name or Path. While the attack vector is classified as local, the attacker can be remote. The exploitation occurs locally on the victim’s machine after the attacker has gained access to the victim’s Microsoft Outlook account, typically through compromised or stolen credentials.

The attack complexity is rated as high, which implies that an attacker must take several steps to exploit the vulnerability successfully. Specifically, they need to install a malicious form on the victim’s system. User interaction is also required; the victim must open a malicious email and perform specific actions to trigger the vulnerability. Notably, the Preview Pane in Outlook serves as an attack vector, making it easier for attackers to exploit this flaw without requiring extensive user engagement.

As was the case with CVE-2024-30103, this again is a zero-click vulnerability and does not require user interaction on systems with Microsoft’s auto-open email feature enabled, Morphisec explained. To address these vulnerabilities, users are advised to update their systems promptly.

Morphisec’s research involved the analysis of Outlook’s codebase through fuzzing and reverse engineering. Their findings were reported to Microsoft as part of the responsible disclosure process. Both issues were addressed by the tech giant in its August 2024 patch release. In addition to CVE-2024-38173, the August patch cycle also included fixes for other vulnerabilities that could potentially be chained together to provide complete control over affected systems.

[single_post_faqs]
Neha Sharma
Neha Sharma
Neha Sharma is a tech-savvy author at The Reportify who delves into the ever-evolving world of technology. With her expertise in the latest gadgets, innovations, and tech trends, Neha keeps you informed about all things tech in the Technology category. She can be reached at neha@thereportify.com for any inquiries or further information.

Share post:

Subscribe

Popular

More like this
Related

Revolutionary Small Business Exchange Network Connects Sellers and Buyers

Revolutionary SBEN connects small business sellers and buyers, transforming the way businesses are bought and sold in the U.S.

District 1 Commissioner Race Results Delayed by Recounts & Ballot Reviews, US

District 1 Commissioner Race in Orange County faces delays with recounts and ballot reviews. Find out who will come out on top in this close election.

Fed Minutes Hint at Potential Rate Cut in September amid Economic Uncertainty, US

Federal Reserve minutes suggest potential rate cut in September amid economic uncertainty. Find out more about the upcoming policy decisions.

Baltimore Orioles Host First-Ever ‘Faith Night’ with Players Sharing Testimonies, US

Experience the powerful testimonies of Baltimore Orioles players on their first-ever 'Faith Night.' Hear how their faith impacts their lives on and off the field.