References https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413 https://nvd.nist.gov/vuln/detail/CVE-2024-21413 https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture/ https://github.com/ThemeHackers/CVE-2024-21413 https://www.armis.com/threat-alert/microsoft-outlook-remote-code-execution-vulnerability/ https://www.cve.org/CVERecord?id=CVE-2024-21413 https://github.com/xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability https://www.rapid7.com/db/vulnerabilities/microsoft-office-cve-2024-21413/ https://www.stormshield.com/news/security-alert-microsoft-office-cve-2024-21413-stormshield-products-response/ https://blog.senthorus.ch/posts/cve_2024_21413/
Related VulnerabilitiesPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)PoCdzzoffice-installer: DzzOffice - Installer Page Exposure泛微e-office /iWebOffice/Signature/SignatureDel.php SQL 注入漏洞万户 ezOFFICE /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../platform/bpm/work_flow/operate/wf_relation.jsp SQL 注入漏洞PoCCVE-2026-25512: Group-Office < 26.0.5 - Remote Code ExecutionPoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2025-5301: ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site ScriptingPoCsharepoint-lists-api-disclosure: Microsoft SharePoint - List API DisclosurePoCsharepoint-layouts-disclosure: Microsoft SharePoint - Layouts Disclosure