0-Click Outlook RCE Vulnerability Triggered When Email is Clicked
NetSPI discovered that Microsoft Outlook is vulnerable to authenticated remote code execution (CVE-2024-21378) due to improper validation of synchronized form objects. By manipulating a configuration…