Michael Gorelik & Arnold Osipov: Outlook RCE Chaos — CVE-2024-30103
A DEF CON 32 talk where researchers Michael Gorelik and Arnold Osipov present a series of vulnerabilities in Microsoft Outlook that enable remote code execution.
They demonstrate how even an empty email with an invisible form can trigger code execution due to quirks in COM object handling.
The talk also explores related vulnerabilities that can leak NTLM credentials, traces the evolution of this attack surface, and provides recommendations for defense.
They demonstrate how even an empty email with an invisible form can trigger code execution due to quirks in COM object handling.
The talk also explores related vulnerabilities that can leak NTLM credentials, traces the evolution of this attack surface, and provides recommendations for defense.