Microsoft Outlook是美国微软(Microsoft)公司的一套电子邮件应用程序。 Microsoft Office Outlook存在安全漏洞。以下产品和版本受到影响:Microsoft Office 2019 for 32-bit editions,Microsoft Office 2019 for 64-bit editions,Microsoft 365 Apps for Enterprise for 32-bit Systems,Microsoft 365 Apps for Ente
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Microsoft 365 Apps for Enterprise | 16.0.1< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Office 2019 | 19.0.0< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Office LTSC 2021 | 16.0.1< https://aka.ms/OfficeSecurityReleases |
affected |
| Microsoft | Microsoft Outlook 2016 | 16.0.0.0< 16.0.5435.1000 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft 365 Apps for Enterprise | 16.0.1 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Office 2019 | 19.0.0 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Office LTSC 2021 | 16.0.1 ~ https://aka.ms/OfficeSecurityReleases | - |
|
| Microsoft | Microsoft Outlook 2016 | 16.0.0.0 ~ 16.0.5435.1000 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via COM DLLs. The exploit utilizes a modified version of Ruler to send a malicious form as an email, triggering the execution upon user interaction within the Outlook thick client. | https://github.com/d0rb/CVE-2024-21378 | POC Details |
| 2 | PoC Exploit for Outlook Vulnerability, CVE-2024-21378 | https://github.com/JohnHormond/CVE-2024-21378 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-21401 | 9.8 CRITICAL | Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability |
| CVE-2024-21413 | 9.8 CRITICAL | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2024-21410 | 9.8 CRITICAL | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2024-21364 | 9.3 CRITICAL | Microsoft Azure Site Recovery Elevation of Privilege Vulnerability |
| CVE-2024-21403 | 9.0 CRITICAL | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerabi |
| CVE-2024-21376 | 9.0 CRITICAL | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerabil |
| CVE-2024-21375 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21353 | 8.8 HIGH | Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability |
| CVE-2024-21352 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21350 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21366 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21349 | 8.8 HIGH | Microsoft ActiveX Data Objects Remote Code Execution Vulnerability |
| CVE-2024-21369 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21391 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21372 | 8.8 HIGH | Windows OLE Remote Code Execution Vulnerability |
| CVE-2024-21361 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21365 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21370 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21368 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
| CVE-2024-21367 | 8.8 HIGH | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
Showing top 20 of 72 CVEs. View all on vendor page → →
No comments yet