Executive brief
Microsoft Outlook contains an improper input validation vulnerability, known as 'MonikerLink', that allows for remote code execution. An attacker can bypass Office Protected View to open malicious files in editing mode, potentially leading to full system compromise without user interaction.
Affected products
- Microsoft 365 Apps for Enterprise
- Microsoft Office Long Term Servicing Channel 2021
- Microsoft Office 2019
- Microsoft Office 2016
Timeline
- 2024-11-21: disclosed: Initial disclosure and technical description by Check Point Research.
- 2025-02-06: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.
- 2025-02-27: other: CISA due date for federal agencies to apply mitigations.