CVE-2024-42220

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Dec 18, 2024
Updated: Dec 19, 2024
CWE ID 347

Summary

CVE-2024-42220 is a library injection vulnerability affecting Microsoft Outlook 16.83.3 on macOS. Malicious actors can exploit this issue by injecting a specially crafted library into Outlook. This allows the attacker to bypass permissions and gain access to the vulnerable application's privileges. A malicious application can then be started, taking advantage of Outlook's access rights to execute potentially harmful code. Users are advised to update their Outlook software to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share