Go back

CVE-2024-38021: Moniker RCE Vulnerability Uncovered in Microsoft Outlook

Michael Gorelik
Michael Gorelik
09 Jul 2024
4 min read
Threat Research
CVE-2024-38021

Morphisec researchers have identified a significant vulnerability, CVE-2024-38021 โ€” a zero-click remote code execution (RCE) vulnerability that impacts most Microsoft Outlook applications. ย 

Unlike the previously discovered vulnerability CVE-2024-30103 disclosed in June โ€”which required authentication (at least an NTLM token)โ€” this new vulnerability does not require any authentication.ย 

CVE-2024-38021ย Vulnerability Details and Technical Impact

If exploited, CVE-2024-38021ย can lead to potential data breaches, unauthorized access, and other malicious activities.ย 

Microsoft has assessed this vulnerability with an “Important” severity rating. Their assessment differentiates between trusted and untrusted senders, noting that while the vulnerability is zero-click for trusted senders, it requires one click user interaction for untrusted senders.ย 

Given the broader implications of this vulnerability, particularly its zero-click vector for trusted senders and its potential for much wider spread impact, we have requested Microsoft to reassess the severity and label it as “Critical.” This reassessment is crucial to reflect the true risk and ensure adequate attention and resources are allocated for mitigation. The complexity for this RCE is higher than CVE-2024-30103, reducing the likelihood of short-term exploitation. However, the chaining of this vulnerability with another could potentially simplify the attack process.ย 

Timeline of Events

April 21, 2024: The vulnerability was initially reported to Microsoft by Morphisec researchers as part of responsible disclosure policy. ย 

April 26, 2024: The vulnerability was confirmed. ย 

July 9, 2024: Microsoft included a patch for CVE-2024-38021ย as part of its Patch Tuesday updates. ย 

We commend Microsoft for addressing this vulnerability relatively quickly, especially considering its problematic nature and the complexity of the previous patch.ย 

hs-cta-img-8fcef7be-a943-4617-a8f0-6387b82ffeeb ย 

Exploitation Riskย 

Given its zero-click nature (for trusted senders) and lack of authentication requirements, CVE-2024-38021ย poses a severe risk. Attackers could exploit this vulnerability to gain unauthorized access, execute arbitrary code, and cause substantial damage without any user interaction. The absence of authentication requirements makes it particularly dangerous, as it opens the door to widespread exploitation.ย 

Patch Release and Urgent Call to Actionย 

Patch Deployment: Ensure that all Microsoft Outlook and Office applications are updated with the latest patches as soon as they are available.ย 

Email Security: Implement robust email security measures, including disabling automatic email previews if possible.ย 

User Awareness: Educate users about the risks associated with opening emails from unknown or suspicious sources.ย 

Ensuring optimal and comprehensive coverage across the security stack with EDR and Automated Moving Target Defense (AMTD) reduces further risk and will offer endpoint assurance against known and unknown attacks.ย 

Research and Discovery Processย 

Morphisecโ€™s research involved extensive fuzzing and reverse engineering of Microsoft Outlook’s codebase to identify the specific conditions that led to the discovery of this Microsoft Outlook vulnerability. The findings were then thoroughly documented and reported to Microsoft (as per responsible disclosure process), ensuring a collaborative approach to addressing the issue.ย 

Technical Details and Proof of Conceptย 

The Morphisec Threat Labs team presented their technical findings aboutย CVE-2024-30103 and CVE-2024-38021 on the main stage at DEF CON 32. If you weren’t able to attend in person, watch the on-demand webinar to hear directly from those that discovered these vulnerabilities and to learn more about the vulnerabilities. Watch now.

ย  hs-cta-img-40d5b46a-ce48-42ef-8281-12ae60f3e796

How Morphisec can Helpย 

At Morphisec, we utilize Automated Moving Target Defense (AMTD) techniques to significantly reduce the risk of exploitation from vulnerabilities like CVE-2024-38021. By continuously and dynamically altering the attack surface, Morphisec AMTD creates a highly challenging environment for potential attackers. This innovative and preventative approach strengthens the protection of our clients against a broad spectrum of sophisticated cyber threats.ย 

Additionally, Morphisecโ€™s AMTD technology acts as a virtual patch and compensating control for unpatched vulnerabilities. It proactively thwarts attacks on unpatched operating systems and application vulnerabilities by disrupting attack pathways, effectively dismantling an attackerโ€™s framework.ย ย 

Experience Morphisec firsthand โ€” schedule a demo today.ย 

Ransomware Free Guarantee - Get a Demo

About the author

Michael Gorelik headshot

Michael Gorelik

Chief Technology Officer

Morphisec CTO Michael Gorelik leads the malware research operation and sets technology strategy. He has extensive experience in the software industry and leading diverse cybersecurity software development projects. Prior to Morphisec, Michael was VP of R&D at MotionLogic GmbH, and previously served in senior leadership positions at Deutsche Telekom Labs. Michael has extensive experience as a red teamer, reverse engineer, and contributor to the MITRE CVE database. He has worked extensively with the FBI and US Department of Homeland Security on countering global cybercrime. Michael is a noted speaker, having presented at multiple industry conferences, such as SANS, BSides, and RSA. Michael holds Bsc and Msc degrees from the Computer Science department at Ben-Gurion University, focusing on synchronization in different OS architectures. He also jointly holds seven patents in the IT space.

Stay up-to-date

Get the latest resources, news, and threat research delivered to your inbox.

Morphisec Launches AI Usage Control Governing AI on the Endpoint