Netskope Threat Labs

FILE-OFFICE Microsoft Outlook remote code execution attempt

IPS-CFW

2 SIDs: 63053, 63312

Detects email or calendar content exploiting CVE-2024-21413, the Outlook MonikerLink flaw that sends credentials or runs code when the message renders. The rule matches the file protocol links carrying crafted network paths that bypass Outlook's protected view checks.