
Educational lab and PoC demonstrating CVE-2024-21413 Outlook Moniker Link attack to leak netNTLMv2 hashes via crafted HTML email.
Educational lab notes and a small Proof of Concept (PoC) demonstrating the CVE-2024-21413 attack flow in a controlled environment (TryHackMe-style lab).
⚠️ For educational purposes only. Do not use against systems you don’t own or have explicit permission to test.
Microsoft Outlook can render HTML emails and handle different URL schemes. This lab explores how a crafted Moniker Link using the file:// scheme and a special character (!) can bypass Outlook's Protected View behavior and trigger an SMB authentication attempt, potentially leaking the victim’s netNTLMv2 hash.
file:// Moniker Link! character behavior in the Moniker Link