Watch out for MonikerLink flaw – Outlook users at risk

February 18, 2024
1 min read




Summary of New MonikerLink Flaw Article

TLDR:

  • #MonikerLink security flaw in Microsoft Outlook allows hackers to execute arbitrary code
  • CVSS score of 9.8 out of 10, critical severity, high exploitability

The #MonikerLink security flaw in Microsoft Outlook has been discovered by Check Point Research. This vulnerability, with a CVSS score of 9.8 out of 10, allows hackers to execute arbitrary code on targeted devices, potentially leading to system compromise, denial of service, and data breach. The flaw misuses the Component Object Model (COM) on Windows, leading to unauthorized code execution and leaking of local NTLM credential information. Threat actors can exploit this vulnerability to steal data, install malware, and compromise the system with minimal user interaction. The exploit occurs when Outlook processes “file://” hyperlinks, connecting to a remote server controlled by attackers. This vulnerability poses a significant risk to organizational security, emphasizing the importance of applying patches, following security practices, and being vigilant against suspicious emails.


Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and