Thursday, July 11, 2024

Critical vulnerability in Outlook

  Microsoft Outlook. Outlook is Microsoft email system. Server, client, application. Part of several Microsoft subscriptions.

 The vulnerability, tracked as CVE-2024-38021, allows an attacker to take control of the system it is running on, no user interaction, no authentication, full control, no click, remote code execution. 

 The vulnerability along with 142 others was patched with the July 9 Microsoft Patch Tuesday monthly security patch release. Thus very important to apply security updates. Recall June had a fix for the very critical Microsoft Windows wireless driver stack.

 You may have other email systems/clients BUT outlook may be started as part of Windows startup.

No comments:

Post a Comment