Outlook Unleashing RCE Chaos CVE 2024 30103
Michael Gorelik, Arnold Osipov
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
In this DEF CON 32 presentation, Michael Gorelik and Arnold Osipov from Morphic shed light on a critical and often overlooked aspect of cybersecurity: the incompleteness of security patches. Their talk, "Outlook Unleashing RCE Chaos CVE 2024 30103," dissects how seemingly comprehensive security updates for Microsoft Outlook can fall short, leaving systems vulnerable to Remote Code Execution (RCE). The speakers specifically detail their discovery of new RCE vulnerabilities, including CVE-2024-30103, by meticulously analyzing prior patches issued by Microsoft. This research underscores a fundamental challenge in software security: the difficulty of fully eradicating entire classes of vulnerabilities with targeted fixes.

Key moments
- 0:00 Introduction: Patches often fail, new vulnerabilities emerge
- 0:30 Talk's objective: Sharing new patch-related vulnerabilities
- 1:55 Speakers introduction: Michael Gorelik & Arnold Osipov
- 2:30 Motivation: Reviewing critical RCE vulnerabilities
- 2:50 Focus: Form injection and compound moniker RCEs
Outlook Unleashing RCE Chaos CVE 2024 30103
Speakers: Michael Gorelik, Chief Technology Officer and Founder, Morphic; Arnold Osipov, Malware Research Lead, Morphic
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=GwwxeY11xMI
Overview
In this DEF CON 32 presentation, Michael Gorelik and Arnold Osipov from Morphic shed light on a critical and often overlooked aspect of cybersecurity: the incompleteness of security patches. Their talk, "Outlook Unleashing RCE Chaos CVE 2024 30103," dissects how seemingly comprehensive security updates for Microsoft Outlook can fall short, leaving systems vulnerable to Remote Code Execution (RCE). The speakers specifically detail their discovery of new RCE vulnerabilities, including CVE-2024-30103, by meticulously analyzing prior patches issued by Microsoft. This research underscores a fundamental challenge in software security: the difficulty of fully eradicating entire classes of vulnerabilities with targeted fixes.
The core of Morphic's findings revolves around two significant categories of Outlook vulnerabilities: form injection and compound monikers. While previous research groups like Net Spy and Checkpoint had identified and reported RCEs within these mechanisms, Morphic's work demonstrates that Microsoft's subsequent patches were often too narrow in scope. By performing patch analysis, Gorelik and Osipov were able to identify logical flaws or alternative control flows that bypassed the intended security fixes, leading to the discovery of fresh, exploitable vulnerabilities.
This presentation is crucial for both security researchers and defenders, as it challenges the assumption that applying vendor patches guarantees complete protection. It highlights that critical RCE flaws, particularly in widely used applications like Microsoft Outlook, can persist even after official security updates. The speakers' methodology of scrutinizing patches provides a valuable blueprint for uncovering residual vulnerabilities, emphasizing the ongoing arms race between attackers and defenders in the complex landscape of enterprise software security.
Background
▶ Watch: Introduction: Patches often fail, new vulnerabilities emerge (0:00)
Microsoft Outlook, as a ubiquitous communication platform in enterprise environments, presents a high-value target for attackers. Its complex architecture, handling everything from basic email to advanced calendaring and task management, relies on intricate underlying mechanisms, some of which have historically proven to be fertile ground for security vulnerabilities, including RCE. The talk's motivation stems from Morphic's commitment to reviewing the most critical RCE vulnerabilities, particularly those that impact widely deployed software.
The speakers contextualized their research by referencing prior significant work in the field. The Net Spy group had previously conducted "amazing work" on the form injection category of vulnerabilities in Outlook. These flaws typically led to RCE but often required some form of prior authentication. Form injection exploits weaknesses in Outlook's handling of custom forms, which are integral to how messages and other items are rendered and processed. For instance, a "recall message" functionality, which allows a sender to delete an email from a recipient's inbox, relies on a complex rendering and synchronization mechanism based on forms. This underlying system, designed for legitimate functionality, can be manipulated by an attacker to inject malicious forms that execute arbitrary code.
Another category of RCE vulnerabilities, compound monikers, was highlighted, with Checkpoint credited for "great research and a great work discovering some vulnerabilities during the year" in this area. Compound monikers are an OLE (Object Linking and Embedding) technology that allows for the creation of references to objects, potentially across different applications or even network boundaries. Misconfigurations or vulnerabilities in their parsing and handling can lead to unauthorized code execution. While the exact technical details of Checkpoint's findings or the nature of the RCE were not elaborated upon in the provided transcript, their existence underscores the multifaceted attack surface presented by Outlook's object-oriented underpinnings.
It is important to note what was explicitly outside the scope of this presentation. The speakers clarified that they would not be discussing Visual Basic for Applications (VBA) execution within forms. This particular attack vector was extensively covered by Ethan Stevens in 2017, leading Microsoft to implement significant hardening measures to prevent the default execution of VBA code embedded in forms. This distinction is crucial, as it indicates that the RCEs discussed by Morphic exploit different, more subtle weaknesses in Outlook's form processing and object handling, rather than relying on older, mitigated VBA execution paths.
The fundamental problem that enables these "patch gap" vulnerabilities, as described by Michael Gorelik, is a vendor's cautious approach to security updates. Citing the recent "mega crash from a Crowdstrike update" that caused widespread blue screens, Gorelik explained that vendors often "try to solve only the specific problem" to avoid unintended side effects or breaking existing functionality. While understandable from a stability perspective, this narrow focus can inadvertently leave related control flows or slightly modified attack paths unaddressed. This creates an opportunity for investigative researchers to perform patch analysis, comparing the patched version of software with the unpatched version to identify precisely what changed and, more importantly, what didn't. By understanding the intent and limitations of a patch, researchers can then discover "additional vulnerabilities that are within the code" that the original patch failed to fully mitigate.
Key Findings
▶ Watch: Talk's objective: Sharing new patch-related vulnerabilities (0:30)
The central and most impactful finding presented by Michael Gorelik and Arnold Osipov is that Microsoft's security patches for critical Outlook Remote Code Execution (RCE) vulnerabilities are often incomplete, leaving significant attack surface unaddressed. Through rigorous patch analysis, the Morphic team uncovered new vulnerabilities, including the specifically named CVE-2024-30103, which were essentially bypasses or logical extensions of previously patched RCEs. This directly challenges the common assumption that applying a vendor-issued security update provides a comprehensive fix for a reported vulnerability.
The speakers highlighted two primary categories of vulnerabilities where these incomplete patches were observed: form injection and compound monikers. In both instances, prior research had identified RCE vectors, leading Microsoft to issue patches. However, Morphic's detailed examination revealed that these patches addressed only specific manifestations of the vulnerabilities, failing to account for all potential attack paths or variations. This allowed the Morphic team to discover "additional vulnerabilities by purely looking at the patch," effectively demonstrating that the original fixes "doesn't really do the trick."
For form injection, the finding was that while previous RCEs in this category might have required prior authentication, the incomplete nature of the patches meant that malicious forms could still be utilized to achieve RCE. The intricate mechanism behind Outlook forms, which governs everything from message rendering to background synchronization (e.g., in recall messages), was not fully secured. This allowed attackers to inject full malicious forms, rather than merely modifying existing ones, to trigger RCE.
Regarding compound monikers, while specific technical details were not fully elaborated in the provided transcript, the speakers affirmed that this category also leads to RCE and that Checkpoint's prior discoveries were similarly met with insufficient patches. The implication is that the underlying object handling and referencing mechanisms, which compound monikers exploit, still contained flaws that could be leveraged for remote code execution despite Microsoft's patching efforts.
Ultimately, the key finding is a stark reminder of the iterative nature of vulnerability discovery and exploitation. It underscores that a patch, while necessary, is not always a definitive solution. Instead, it often creates a new puzzle for skilled attackers and researchers: understanding the patch's limitations to discover the next generation of vulnerabilities. The discovery of CVE-2024-30103 and related flaws through this methodology provides concrete evidence of these "patch gap" RCEs in a widely used and critical application like Microsoft Outlook.
Technical Deep Dive
▶ Watch: Speakers introduction: Michael Gorelik & Arnold Osipov (1:55)
The technical core of Morphic's research lies in exploiting the inherent complexity of Microsoft Outlook's internal mechanisms, specifically its reliance on forms and the subsequent analysis of how patches attempt (and sometimes fail) to secure these mechanisms. The talk introduces the concept of Outlook forms as fundamental building blocks for various interactions, extending beyond simple email messages to include complex background processes.
Outlook messages, at their essence, are based on forms. This means that the visual layout, interactive elements, and underlying logic of an email or other Outlook item are defined by a form structure. Beyond the visible interface, forms drive significant hidden functionality. A prime example provided by the speakers is the recall message feature. When a user sends a recall message, it triggers a sophisticated behind-the-scenes process: "something there activates and starts to delete the email from the inboxes of your manager." This seemingly simple action involves a rendering mechanism and the synchronization of forms across different Outlook clients and mailboxes. This intricate dance of form rendering and synchronization, designed for legitimate purposes, becomes a critical attack surface when vulnerabilities are present.
The speakers explained that their approach involved leveraging this form synchronization mechanism to inject malicious forms. Unlike simply modifying an existing form (a capability available through Outlook's developer mode, allowing users to add buttons or sounds), the goal was to inject a full, custom-designed malicious form into the system. The transcript hints that the RCE vector is not through Visual Basic for Applications (VBA), which was a known attack vector in 2017 but has since been hardened by Microsoft following research by Ethan Stevens. This implies that the RCE relies on a more fundamental flaw in how Outlook processes and renders the form's structure or embedded objects, rather than direct script execution.
While the specific exploit chain for CVE-2024-30103 (a form injection RCE) was not fully detailed in the provided transcript, the general principle involves crafting a specially malformed or constructed form that, when processed by a vulnerable Outlook client, triggers an unintended code execution. This could involve manipulating properties within the form that, during rendering or synchronization, cause memory corruption, type confusion, or an unsafe deserialization of objects, ultimately leading to arbitrary code execution in the context of the Outlook process. The "prior authentication" requirement mentioned for some form injection vulnerabilities implies that an attacker might need to be an authenticated user on the network or have compromised credentials to send the malicious form in certain scenarios. However, the incompleteness of patches suggests that even authenticated RCEs remain highly critical, as an attacker could leverage them for privilege escalation or lateral movement within an organization.
The second category discussed, compound monikers, also represents a powerful RCE vector. Monikers are objects in Windows that represent and provide access to other objects. Compound monikers combine multiple monikers to create complex references. While the transcript did not delve into the specific technicalities of the compound moniker RCEs discovered by Morphic or Checkpoint, these typically involve vulnerabilities in the parsing or resolution of these object references. An attacker could craft a malicious compound moniker that, when Outlook attempts to resolve it, leads to an unsafe operation, such as loading an arbitrary DLL, executing a command, or triggering a vulnerable COM object method. The fact that patches for these vulnerabilities were also found to be insufficient highlights a broader issue with Outlook's handling of external object references and its deserialization processes.
The overarching technical methodology employed by Morphic is patch analysis. This involves obtaining the original vulnerable binaries and the patched binaries from Microsoft's updates (e.g., June and July patches mentioned). Using tools like disassemblers and diffing engines, researchers can identify the exact code changes made by Microsoft. By analyzing these changes, they can understand the intended fix. If the fix is too narrow, only addressing a specific input or code path, researchers can then craft new inputs or exploit alternative code paths that bypass the patch, revealing a new vulnerability. This process demands deep reverse engineering skills and a thorough understanding of the targeted software's architecture.
Demo / Proof of Concept
▶ Watch: Motivation: Reviewing critical RCE vulnerabilities (2:30)
While the provided transcript snippet does not detail a specific live demonstration or proof-of-concept execution, the speakers clearly state their intention to "show how the patch doesn't really do the trick" and "how we utilize that to inject malicious forms." This implies that their research culminated in working exploits for the identified vulnerabilities. The successful discovery of CVE-2024-30103 and other "patch gap" RCEs strongly suggests that Morphic developed and tested proof-of-concept code to validate their findings, demonstrating the practical feasibility of their form injection techniques and the bypasses of the original patches. Such demonstrations are standard practice in security conferences to concretely illustrate the impact of vulnerabilities and the effectiveness of the researchers' methodology.
Defensive Implications
▶ Watch: Focus: Form injection and compound moniker RCEs (2:50)
The findings presented by Morphic carry profound defensive implications for organizations relying on Microsoft Outlook. The primary takeaway is that applying vendor patches, while essential, is not a silver bullet and may not guarantee complete protection against all related vulnerabilities. This necessitates a more sophisticated and proactive approach to security.
- Skepticism Towards Patch Completeness: Defenders must adopt a healthy skepticism regarding the completeness of security patches, especially for complex RCE vulnerabilities in widely used software. It's crucial to understand that a patch might fix a specific exploit vector but leave an entire class of vulnerabilities open to subtle variations or alternative attack paths. Organizations should not assume that a "patched" status equates to absolute security for a given vulnerability category.
- Proactive Patch Analysis (for Advanced Teams): For highly mature security teams, particularly those involved in red teaming, vulnerability research, or incident response, considering internal patch analysis of critical security updates can be a valuable, albeit resource-intensive, defensive strategy. By understanding how a vendor patched a vulnerability, these teams can proactively identify potential bypasses or related flaws before they are exploited in the wild.
- Layered Security and Defense-in-Depth: Given the persistence of RCE vulnerabilities like CVE-2024-30103 in a critical application like Outlook, a robust defense-in-depth strategy is paramount. Relying on a single control will eventually fail. This means implementing multiple layers of security, including:
- Endpoint Detection and Response (EDR) / Extended Detection and Response (XDR): These solutions are critical for detecting unusual process behavior, suspicious network connections originating from Outlook, or attempts to execute arbitrary code. Modern EDRs can often identify post-exploitation activities even if the initial RCE is successful.
- Application Whitelisting/Control: Strictly control which applications and scripts are allowed to run on endpoints. While challenging for Outlook itself, this can prevent malicious payloads delivered via RCE from executing further stages.
- Network Segmentation: Isolate critical systems and users to limit the lateral movement potential of an attacker who successfully exploits an Outlook RCE.
- Least Privilege: Ensure users operate with the minimum necessary privileges to perform their tasks. This limits the damage an attacker can inflict if they gain RCE in a user's context.
- Enhanced Vulnerability Management: Organizations should refine their vulnerability management processes to not only prioritize RCEs but also track ongoing research into specific vulnerability classes (like form injection or compound monikers). Staying informed about research from groups like Morphic, Net Spy, and Checkpoint can provide early warnings about potential patch gaps.
- User Awareness and Phishing Training (Still Relevant): While some RCEs might not require user interaction, many still leverage social engineering. Ongoing user education about phishing, suspicious attachments, and unusual email behavior remains a critical first line of defense, even against sophisticated RCEs that might eventually bypass technical controls.
- Continuous Monitoring and Threat Hunting: Proactive monitoring of Outlook environments for indicators of compromise (IOCs) related to form injection, unusual Outlook process spawns, or network activity is crucial. Threat hunting exercises, specifically looking for these types of attacks, can help uncover ongoing compromises.
In essence, the talk serves as a call for increased vigilance and a more nuanced understanding of software security. Defenders must move beyond a simple "patch-and-pray" mentality and embrace a continuous, multi-layered approach to protect against persistent and evolving RCE threats.
Key Takeaways
- Patches are Not Always Complete: Security updates, particularly for complex vulnerabilities like RCEs in applications like Outlook, can be incomplete, leaving related attack vectors open.
- Patch Analysis is a Powerful Discovery Method: Meticulously analyzing the differences between patched and unpatched software versions can reveal "patch gap" vulnerabilities and new RCEs, as demonstrated by Morphic.
- Outlook's Form Mechanism is a Critical Attack Surface: The underlying form rendering and synchronization mechanisms in Outlook, used for features like recall messages, can be abused to inject malicious forms and achieve Remote Code Execution.
- CVE-2024-30103 Highlights Persistent RCEs: This specific vulnerability, discovered by Morphic, exemplifies how RCEs related to form injection can persist despite previous patching efforts.
- Layered Security is Essential: Defenders cannot rely solely on vendor patches. A robust defense-in-depth strategy, including EDR, application control, and network segmentation, is crucial to mitigate the impact of incomplete patches and successful RCEs.
- Understanding Vulnerability Classes is Key: Awareness of categories like form injection and compound monikers, and the history of research by groups like Net Spy and Checkpoint, provides critical context for anticipating and defending against future threats.
About the Speaker(s)
Michael Gorelik is the Chief Technology Officer and founder of Morphic. With approximately 20 years of experience in cybersecurity, Michael is a seasoned expert in the field. His extensive background includes significant achievements such as discovering one of the largest supply chain attacks in history, specifically the Ccleaner incident. Michael brings a wealth of knowledge in various domains of cybersecurity, including reverse engineering, red teaming, and blue teaming.
Arnold Osipov leads the malware research efforts at Morphic. Arnold specializes in patch analysis, a critical area of vulnerability research where he "pokes with some patch analysis for fun and profit and product, of course." His work focuses on dissecting security updates to identify potential bypasses or unaddressed vulnerabilities, directly contributing to the discoveries shared in this talk.
Reviews
Heather Calloway (CISO) — MUST SEE
This DEF CON presentation by Morphic delivers a critical message for every security leader: vendor patches, especially for complex RCEs in ubiquitous software like Microsoft Outlook, are often incomplete. By detailing their discovery of CVE-2024-30103 through meticulous patch analysis, Gorelik and Osipov challenge the assumption of full protection post-patching. The talk provides actionable insights for reinforcing defense-in-depth strategies and fostering a necessary skepticism about patch completeness, making it essential viewing for anyone accountable for enterprise risk.