← לוח פגיעויות

CVE-2024-21413

קריטית 9.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Microsoft Outlook Improper Input Validation Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

Microsoft Outlook Remote Code Execution Vulnerability

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
95% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-20

מוצרים מושפעים

microsoft: 365 apps; microsoft: office 2016; microsoft: office 2019; microsoft: office long term servicing channel

קישורים