What happened
Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.
Affected versions
Office Outlook: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
PoC-in-GitHub · duy-31/CVE-2024-21413Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC★ 158duy-312024-02-15CandidatePoC-in-GitHub · xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-VulnerabilityMicrosoft-Outlook-Remote-Code-Execution-Vulnerability★ 771xaitax2024-02-16CandidatePoC-in-GitHub · r00tb1t/CVE-2024-21413-POCMicrosoft Outlook Information Disclosure Vulnerability (leak password hash) - CVE-2024-21413 POC★ 17r00tb1t2024-02-16CandidatePoC-in-GitHub · CMNatic/CVE-2024-21413CVE-2024-21413 PoC for THM Lab★ 281CMNatic2024-02-17CandidatePoC-in-GitHub · MSeymenD/CVE-2024-21413CVE-2024-21413 Açığını Kullanarak Giriş Bilgilerini Alma★ 0MSeymenD2024-02-19CandidatePoC-in-GitHub · Mdusmandasthaheer/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability★ 5Mdusmandasthaheer2024-02-20CandidatePoC-in-GitHub · ahmetkarakayaoffical/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-VulnerabilityBu betik, Microsoft Outlook'ta keşfedilen ve CVSS değeri 9.8 olan önemli bir güvenlik açığı olan CVE-2024-21413 için bir kavram kanıtı (PoC) sunmaktadır. MonikerLink hatası olarak adlandırılan bu güvenlik açığı, yerel NTLM bilgilerinin potansiyel sızıntısı ve uzaktan kod çalıştırma olasılığı dahil olmak üzere geniş kapsamlı etkilere sahiptir.★ 4ahmetkarakayaoffical2024-02-23CandidatePoC-in-GitHub · dshabani96/CVE-2024-21413★ 2dshabani962024-02-29CandidatePoC-in-GitHub · KartheekKandalam99/SVPT_CW_2CVE-2024-21413 Setup for CW★ 0KartheekKandalam992024-04-13CandidatePoC-in-GitHub · X-Projetion/CVE-2024-21413-Microsoft-Outlook-RCE-ExploitCVE-2024-21413 Microsoft Outlook RCE Exploit★ 2X-Projetion2024-05-03CandidatePoC-in-GitHub · th3Hellion/CVE-2024-21413★ 0th3Hellion2024-05-11CandidatePoC-in-GitHub · ShubhamKanhere307/CVE-2024-21413This script is the Proof of Concept (PoC) of the CVE-2024-21413, a significant security vulnerability discovered in the Microsoft Windows Outlook having a strong 9.8 critical CVSS score. Named as #MonikerLink Bug, this vulnerability allows the attacker to execute the arbitrary code remotely on the victim's machine, thus becomes a full-fledged RCE.★ 0ShubhamKanhere3072024-06-18CandidatePoC-in-GitHub · olebris/CVE-2024-21413CVE-2024-21413 PoC★ 0olebris2024-06-28CandidatePoC-in-GitHub · Redfox-Security/Unveiling-Moniker-Link-CVE-2024-21413-Navigating-the-Latest-Cybersecurity-Landscape★ 0Redfox-Security2024-07-03CandidatePoC-in-GitHub · ThemeHackers/CVE-2024-21413CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC★ 25ThemeHackers2024-08-31CandidatePoC-in-GitHub · D1se0/CVE-2024-21413-Vulnerabilidad-Outlook-LAB★ 4D1se02024-12-04CandidatePoC-in-GitHub · ArtemCyberLab/Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks using email. This showcases how network authentication vulnerabilities and phishing methods can be exploited to compromise systems.★ 0ArtemCyberLab2025-03-25CandidatePoC-in-GitHub · PolarisXSec/CVE-2024-21413★ 1PolarisXSec2025-05-11CandidatePoC-in-GitHub · MQKGitHub/Moniker-Link-CVE-2024-21413★ 0MQKGitHub2025-05-30CandidatePoC-in-GitHub · yass2400012/Email-exploit-Moniker-Link-CVE-2024-21413-★ 0yass24000122025-09-23CandidatePoC-in-GitHub · gurleen-147/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability-PoCThis repository contains research notes and a high-level proof-of-concept (PoC) for CVE-2024-21413, a vulnerability observed in certain mail clients when handling SMB/moniker-style links embedded in messages. The PoC and experiments documented here were performed in a controlled lab environment on systems.★ 2gurleen-1472025-11-06CandidatePoC-in-GitHub · hau2212/Moniker-Link-CVE-2024-21413-On February 13th, 2024, Microsoft announced a Microsoft Outlook RCE & credential leak vulnerability with the assigned CVE of CVE-2024-21413 (Moniker Link). Haifei Li of Check Point Research is credited with discovering the vulnerability. The vulnerability bypasses Outlook's security mechanisms when handing a specific type of hyperlink .★ 0hau22122025-11-20CandidatePoC-in-GitHub · mmathivanan17/CVE-2024-21413Outlook exploitation★ 11mmathivanan172025-11-30CandidatePoC-in-GitHub · eylommaayan/THM---CVE-2024-21413-Moniker-Link-Microsoft-Outlook-ב־13 בפברואר 2024 פרסמה Microsoft חולשת אבטחה חמורה ב־Microsoft Outlook, אשר קיבלה את הזיהוי CVE-2024-21413, ומוכרת בשם Moniker Link Vulnerability. החולשה מאפשרת לתוקף לעקוף את מנגנון Protected View של Outlook★ 0eylommaayan2026-01-01CandidatePoC-in-GitHub · ViniciusFariasDev/cve-2024-21413-outlook-monikerlink-lab★ 0ViniciusFariasDev2026-01-19CandidatePoC-in-GitHub · dionissh/CVE-2024-21413★ 0dionissh2026-01-25CandidatePoC-in-GitHub · securenetexpert/CVE-2024-21413-Moniker-Link-WriteupTechnical write-up on CVE-2024-21413 (Moniker Link vulnerability)★ 0securenetexpert2026-02-07CandidatePoC-in-GitHub · SallocinAvalcante/lab-SMB-responder-CVE-2024-21413Laboratorio criado para PenTest da Vuln CVE 2024-214113(MONIKER LINK).★ 0SallocinAvalcante2026-02-10CandidatePoC-in-GitHub · E-m-e-k-a/Moniker-Link-Lab-SetupPenetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking, and defensive countermeasures★ 0E-m-e-k-a2026-03-08CandidatePoC-in-GitHub · TheMursalin/HTB-Mailing-A-Complete-WalkthroughIf you've been grinding through HackTheBox machines, Mailing is one of those boxes that genuinely teaches you something. It's rated Easy, runs on Windows, and chains together a few real-world vulnerabilities — a directory traversal, a credential leak, CVE-2024-21413, and a LibreOffice macro exploit. Let's walk through it step by step.★ 0TheMursalin2026-03-25CandidatePoC-in-GitHub · pedro-lucas-melo/Estudo-de-Caso-CVE-2024-21413Um estudo de caso do CVE-2024-21413. Usado como parâmetro a sala do TryHackMe Moniker Link (CVE-2024-21413). Feito edições com claude code no exploit.★ 0pedro-lucas-melo2026-04-05CandidatePoC-in-GitHub · FathanahHidayati/https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability★ 0FathanahHidayati2026-04-14CandidatePoC-in-GitHub · bhatbhupendra/Moniker-Link--CVE-2024-21413-★ 0bhatbhupendra2026-04-25CandidatePoC-in-GitHub · KaiHaoChen04/monikerlinktestcve-2024-21413★ 0KaiHaoChen042026-05-12CandidatePoC-in-GitHub · Dhananjayasj/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability★ 0Dhananjayasj2026-05-30CandidatePoC-in-GitHub · H1ssBl1tz/Blind-Trust-CVE-2024-21413-ResearchA security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).★ 0H1ssBl1tz2026-06-23CandidatePoC-in-GitHub · YoguiCR/CVE-2024-21413-Outlook-Assessment★ 0YoguiCR2026-07-04CandidatePoC-in-GitHub · h4cknain/CVE-2024-21413-Microsoft-Outlook-Moniker-Link-VulnerabilityThis repository documents my hands-on analysis of **CVE-2024-21413 (Moniker Link)**, a critical Microsoft Outlook vulnerability that bypasses Protected View to leak Windows NetNTLMv2 credentials via SMB authentication. > **Severity:** Critical (CVSS 9.8)★ 0h4cknain2026-08-05CandidatePoC-in-GitHub · OmarMahmoud1024/tryhackme-monikerlink-writeupTryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.★ 0OmarMahmoud10242026-08-05CandidatePoC-in-GitHub · yfelipecruvinel/tryhackme-moniker-linkDocumentation of my hands-on lab Moniker Link (CVE-2024-21413) completed on TryHackMe.★ 0yfelipecruvinel2026-08-11CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.