{"id":295151,"date":"2025-02-10T09:50:30","date_gmt":"2025-02-10T17:50:30","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=348091"},"modified":"2025-07-01T15:25:42","modified_gmt":"2025-07-01T22:25:42","slug":"microsoft-outlook-has-a-serious-security-issue-even-the-white-house-is-asking-for-it-to-be-fixed","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/microsoft-outlook-has-a-serious-security-issue-even-the-white-house-is-asking-for-it-to-be-fixed\/","title":{"rendered":"Microsoft Outlook has a serious security issue, even the White House is asking for it to be fixed"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The vulnerability CVE-2024-21413 has been classified by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as<strong> a critical flaw affecting several Microsoft Office products, including Outlook.<\/strong><\/p>\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Microsoft Outlook\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/9bc34786-96d1-11e6-ba62-00163ec9f5fa\/1835744102\/microsoft-outlook-Download-Microsoft-Outlook.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Microsoft Outlook<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/microsoft-outlook.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/microsoft-outlook.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">This flaw is related to inadequate input validation that allows attackers to execute arbitrary code on affected systems.<\/p>\n\n\n<p class=\"wp-block-paragraph\">The severity of this vulnerability has been <strong>rated with an alarming score of 9.8 out of 10.<\/strong><\/p>\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">? URGENT: Attackers are exploiting newly discovered flaws in SimpleHelp RMM software to establish persistent access to networks and deploy ransomware.<br><br>CVE-2024-57726, CVE-2024-57727, CVE-2024-57728: Flaws enabling privilege escalation, remote code execution.<br><br>? Secure your\u2026 <a href=\"https:\/\/t.co\/gxw2UBi2zB\">pic.twitter.com\/gxw2UBi2zB<\/a><\/p>&mdash; The Hacker News (@TheHackersNews) <a href=\"https:\/\/twitter.com\/TheHackersNews\/status\/1887733799221666263?ref_src=twsrc%5Etfw\">February 7, 2025<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n<h2 class=\"wp-block-heading\">When it was discovered and how it affects us as users<\/h2>\n\n\n<p class=\"wp-block-paragraph\">Detected in 2024 by researcher Haifei Li from Check Point, the vulnerability allows cybercriminals to send deceptive emails containing malicious hyperlinks.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Through this technique, attackers can bypass the Protected View feature of Outlook, <\/strong>which is designed to open potentially harmful files in read-only mode. In this case, malicious files could be opened in editing mode, significantly increasing the risk of infection.<\/p>\n\n\n<p class=\"wp-block-paragraph\">CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and has set <strong>a three-week deadline, until February 27, 2025, for federal agencies to implement patches<\/strong> or stop using the tool.<\/p>\n\n\n<p class=\"wp-block-paragraph\">Although no real-world abuse has been documented at the time of the patch&#8217;s release, users have been warned that <strong>even simply previewing an email in Outlook may be enough to experience an infection<\/strong>, highlighting the seriousness of the situation.<\/p>\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Microsoft Outlook\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/9bc34786-96d1-11e6-ba62-00163ec9f5fa\/1835744102\/microsoft-outlook-Download-Microsoft-Outlook.jpg\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Microsoft Outlook<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/microsoft-outlook.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/microsoft-outlook.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">In addition to the flaw in Outlook, CISA has listed four other vulnerabilities that also require attention, including issues related to 7-Zip, the Dante control process, SQL injection in CyberoamsOS, and a buffer overflow in Sophos XG Firewall<strong>. All these vulnerabilities must be fixed before March 2025<\/strong>, due to the significant risks they pose to federal entities.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The vulnerability CVE-2024-21413 has been classified by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as a critical flaw affecting several Microsoft Office products, including Outlook. This defect is related to inadequate input validation that allows attackers to execute arbitrary code on affected systems. The severity of this vulnerability has been rated with an alarming score of 9.8 out of 10. When was it discovered and how does it affect us as users? Detected in 2024 by researcher Haifei Li from Check Point, the vulnerability allows cybercriminals to send emails [&hellip;]<\/p>\n","protected":false},"author":9317,"featured_media":295152,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[1015],"tags":[1067],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-295151","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-amazon"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/295151","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9317"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=295151"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/295151\/revisions"}],"predecessor-version":[{"id":309781,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/295151\/revisions\/309781"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/295152"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=295151"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=295151"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=295151"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=295151"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=295151"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=295151"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}