CVE-2024-21402HighCVSS 7.1
Microsoft Outlook Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H) and major loss of integrity (I:H) but have no effect on availability (A:N). What does that mean for this vulnerability? Exploiting this vulnerability could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the files.
What privileges could be gained by an attacker who successfully exploited the vulnerability? The attacker would gain the rights of the user that is running the affected application.
🎯 Affected products2
- Microsoft 365 Apps for Enterprise for 32-bit Systems
- Microsoft 365 Apps for Enterprise for 64-bit Systems
✅ Remediation
KBClick to Run (Security Update) — fixed build https://aka.ms/OfficeSecurityReleases