CVE-2024-30103
published 2024-06-11CVE-2024-30103: Microsoft Outlook Remote Code Execution Vulnerability
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.45%
87.7th percentile
Microsoft Outlook Remote Code Execution Vulnerability
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_outlook_2016 | >= 16.0.0.0 < 16.0.5452.1000 | 16.0.5452.1000 |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | outlook | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_outlook_2016 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector includes the Preview Pane — malicious emails can trigger exploitation without the user opening the message fully ↗
- →Exploitation involves bypassing Outlook registry block lists and creating malicious DLL files on disk — monitor for unexpected DLL creation in Outlook-related paths ↗
- →Attacker must be authenticated with valid Exchange credentials (PR:L) — look for low-privilege Exchange user accounts sending specially crafted emails ↗
- ·Exploit status at time of advisory was not publicly disclosed or actively exploited, but exploitation was rated 'Less Likely' for the latest software release — patch priority should still be high given Preview Pane attack vector ↗
- ·Remediation is delivered via Click-to-Run update mechanism — ensure Microsoft 365 Apps auto-update is enabled and verify patch application via the referenced KB/update packages ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Outlook Remote Code Execution Vulnerability
vendor_msrc·2024-06-11·CVSS 8.8
CVE-2024-30103 [HIGH] CWE-184 Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
Yes, the Preview Pane is an attack vector.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
The attacker must be authenticated using valid Exchange user credentials.
FAQ: How could an attacker exploit this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Outlook registry block lists and enable the creation of malicious DLL files.
Microsoft Office Outlook: Microsoft Office Outlook
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Remed
VulDB
Microsoft Outlook incomplete blacklist
vuldb·2026-05-19·CVSS 8.8
CVE-2024-30103 [HIGH] Microsoft Outlook incomplete blacklist
A vulnerability, which was classified as critical, has been found in Microsoft Outlook. This affects an unknown function. This manipulation causes incomplete blacklist.
This vulnerability is registered as CVE-2024-30103. Remote exploitation of the attack is possible. No exploit is available.
Applying a patch is the recommended action to fix this issue.
GHSA
GHSA-43r8-23m5-329f: Microsoft Outlook Remote Code Execution Vulnerability
ghsa_unreviewed·2024-06-11
CVE-2024-30103 [HIGH] CWE-184 GHSA-43r8-23m5-329f: Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Trendmicro
The June 2024 Security Update Review
blogs_trendmicro·2024-06-11
The June 2024 Security Update Review
# The June 2024 Security Update Review
Get the June 2024 security update and review.
By: Dustin Childs
2024/06/11
Read time: ( words)
Save to Folio
Somehow, we’ve made it to the sixth patch Tuesday of 2024, and Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for June 2024
For June, Adobe released 10 patches addressing 165(!) CVEs in Adobe Cold Fusion, Photoshop, Experience Manager, Audition, Media Encoder, FrameMaker Publishing Server, Adobe Commerce, Substance 3D Stager, Creative Cloud Desktop, and Acrobat Android. The fix for Experience Ma
Talos
Only one critical issue disclosed as part of Microsoft Patch Tuesday
blogs_talos·2024-06-11·CVSS 8.0
CVE-2024-30080 [HIGH] Only one critical issue disclosed as part of Microsoft Patch Tuesday
Microsoft released its monthly security update Tuesday, disclosing 49 vulnerabilities across its suite of products and software.
Of those there is only one critical vulnerability. Every other security issues disclosed this month is considered "important."
The lone critical security issue is CVE-2024-30080, a remote code execution vulnerability due to a use-after-free (UAF) issue in the HTTP handling function of Microsoft Message Queuing (MSMQ) messages.
An adversary can send a specially crafted malicious MSMQ packet to an MSMQ server, potentially allowing them to perform remote code execution on the server side. Microsoft considers this vulnerability “more likely” to be exploited.
There is also a remote code execution vulnerability in Microsoft Outlook, CVE-2024-30103. By successfully
Trendmicro
The June 2024 Security Update Review
blogs_trendmicro·2024-06-11
The June 2024 Security Update Review
## The June 2024 Security Update Review
Get the June 2024 security update and review.
By: Dustin Childs 2024/06/11 Read time: ( words)
Save to Folio
Somehow, we’ve made it to the sixth patch Tuesday of 2024, and Microsoft and Adobe have released their regularly scheduled updates. Take a break from your regular activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for June 2024
For June, Adobe released 10 patches addressing 165(!) CVEs in Adobe Cold Fusion, Photoshop, Experience Manager, Audition, Media Encoder, FrameMaker Publishing Server, Adobe Commerce, Substance 3D Stager, Creative Cloud Desktop, and Acrobat Android. The fix for Experience Ma
Talos
Only one critical issue disclosed as part of Microsoft Patch Tuesday
blogs_talos·2024-06-11·CVSS 8.0
CVE-2024-30080 [HIGH] Only one critical issue disclosed as part of Microsoft Patch Tuesday
## Only one critical issue disclosed as part of Microsoft Patch Tuesday
Microsoft released its monthly security update Tuesday, disclosing 49 vulnerabilities across its suite of products and software.
Of those there is only one critical vulnerability. Every other security issues disclosed this month is considered "important."
The lone critical security issue is CVE-2024-30080 , a remote code execution vulnerability due to a use-after-free (UAF) issue in the HTTP handling function of Microsoft Message Queuing (MSMQ) messages.
An adversary can send a specially crafted malicious MSMQ packet to an MSMQ server, potentially allowing them to perform remote code execution on the server side. Microsoft considers this vulnerability “more likely” to be exploited.
There is also a remote code exec
2024-06-11
Published