TLDR:
- #MonikerLink security flaw in Microsoft Outlook allows hackers to execute arbitrary code
- CVSS score of 9.8 out of 10, critical severity, high exploitability
The #MonikerLink security flaw in Microsoft Outlook has been discovered by Check Point Research. This vulnerability, with a CVSS score of 9.8 out of 10, allows hackers to execute arbitrary code on targeted devices, potentially leading to system compromise, denial of service, and data breach. The flaw misuses the Component Object Model (COM) on Windows, leading to unauthorized code execution and leaking of local NTLM credential information. Threat actors can exploit this vulnerability to steal data, install malware, and compromise the system with minimal user interaction. The exploit occurs when Outlook processes “file://” hyperlinks, connecting to a remote server controlled by attackers. This vulnerability poses a significant risk to organizational security, emphasizing the importance of applying patches, following security practices, and being vigilant against suspicious emails.