Moniker Link (CVE-2024-21413)

https://tryhackme.com/r/room/monikerlink

What does it do:

An unwilling victim clicks on a link in Outlook (versions affected by this shown bellow) This simple act will send the attacker the netNTLMv2 hash of the victim's

How does it work:

The link contains the address of the attacker, by clicking on it, you're initiating SMB (Server Message Block) protocol, potentially triggering an NTLMv2 authentication request. which is used for file sharing by windows, Linux etc. In simple terms, Outlook thinks you want to access files someone sent you and does what it's supposed to do.

The vulnerability is known to affect the following Office releases:

Release
Version

Microsoft Office LTSC 2021

affected from 19.0.0

Microsoft 365 Apps for Enterprise

affected from 16.0.1

Microsoft Office 2019

affected from 16.0.1

Microsoft Office 2016

affected from 16.0.0 before 16.0.5435.1001

Last updated