Skip to main content
Room Banner
Back to all walkthroughs
Room Icon

Moniker Link (CVE-2024-21413)

Max room.

Leak user's credentials using CVE-2024-21413 to bypass Outlook's Protected View.

easy

30 min

114,126

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Lab Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine
Status:Off

On February 13th, 2024, Microsoft announced a Microsoft Outlook & credential leak vulnerability with the assigned of -2024-21413 (opens in new tab) (Moniker Link). Haifei Li of Check Point Research is credited with discovering the vulnerability (opens in new tab).

The vulnerability bypasses Outlook's security mechanisms when handing a specific type of hyperlink known as a Moniker Link. An attacker can abuse this by sending an email that contains a malicious Moniker Link to a victim, resulting in Outlook sending the user's credentials to the attacker once the hyperlink is clicked.

Details relating to the scoring of the vulnerability have been provided in the table below:

Description
Publish dateFebruary 13th, 2024
MS articlehttps://msrc.microsoft.com/update-guide/en-US/vulnerability/-2024-21413 (opens in new tab)
ImpactRemote Code Execution & Credential Leak
SeverityCritical
Attack ComplexityLow
Scoring9.8

The vulnerability is known to affect the following Office releases:

ReleaseVersion
Microsoft Office LTSC 2021affected from 19.0.0
Microsoft 365 Apps for Enterprise
affected from 16.0.1
Microsoft Office 2019
affected from 16.0.1
Microsoft Office 2016
affected from 16.0.0 before 16.0.5435.1001

Learning Objectives

  • How the vulnerability works
  • Understand Outlook's "Protected View"
  • Using the vulnerability to leak credentials from an Outlook client
  • Detection and mitigation measures
Starting the

Note that you will need both the AttackBox and the vulnerable machine attached to this task. To deploy the attached , press the green Start Lab Machine button below.

The machine should launch in a split-screen view. If it doesn't, you can press the blue Show Split View button near the top-right of this page. All of the room can be done in split view, but if you prefer connecting to the machine via , you can use the following credentials:

THM key
Username tryhackme
Password Kkh3gv439dnq!

Deploy both the AttackBox and vulnerable machine in this task. The machine will take about 5 minutes to launch, so for now, complete this task and proceed to the of the room; we will come onto the machine later.

Answer the questions below
What "Severity" rating has the CVE been assigned?