From 3ee72c96e4c98cc35854dc8c2ddbd16f33803c11 Mon Sep 17 00:00:00 2001 From: "Joshua Hitchen (DGov)" <86041569+DGovEnterprise@users.noreply.github.com> Date: Mon, 19 Feb 2024 08:14:09 +0800 Subject: [PATCH] CVE-2024-21413 highlighted --- .../20240214002-Microsoft-Releases-Multiple-Updates.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/advisories/20240214002-Microsoft-Releases-Multiple-Updates.md b/docs/advisories/20240214002-Microsoft-Releases-Multiple-Updates.md index 0fb4694f..89e575b9 100644 --- a/docs/advisories/20240214002-Microsoft-Releases-Multiple-Updates.md +++ b/docs/advisories/20240214002-Microsoft-Releases-Multiple-Updates.md @@ -12,6 +12,7 @@ Microsoft has released security updates to address vulnerabilities in multiple p | **Internet Shortcut Files Security Feature Bypass Vulnerability** | [CVE-2024-21412](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21412) | **High** | 8.1 | **Yes** | 13 Feb, 2024 | | **Windows SmartScreen Security Feature Bypass Vulnerability** | [CVE-2024-21351](https://nvd.nist.gov/vuln/detail/CVE-2024-21351) | **High** | 7.6 | **Yes** | 13 Feb, 2024 | | **Microsoft Exchange Server Elevation of Privilege Vulnerability** | [CVE-2024-21410](https://nvd.nist.gov/vuln/detail/CVE-2024-21410) | **Critical** | 9.8 | **Yes** | 15 Feb, 2024 | +| **Microsoft Outlook Remote Code Execution Vulnerability** | [CVE-2024-21413](https://nvd.nist.gov/vuln/detail/CVE-2024-21413) | **Critical** | 9.8 | **No** | 19 Feb, 2024 | ## What has been observed? @@ -26,3 +27,4 @@ The WA SOC recommends administrators apply the solutions as per vendor instructi - [CISA - Microsoft Releases Security Updates for Multiple Products](https://www.cisa.gov/news-events/alerts/2024/02/13/microsoft-releases-security-updates-multiple-products) - [Internet Shortcut Files Security Feature Bypass Vulnerability](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21412) - [CISA Known Exploited Vulnerabilities ](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) +- [ACSC Outlook Vulnerability](https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/microsoft-office-outlook-remote-code-execution-vulnerability)