CVE-2024-43609

MEDIUM

Microsoft 365 Apps and Office - Exposure of Sensitive Information via Spoofing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-43609. PoCs published by passtheticket.

AI-analyzed exploit summary The repository contains a functional exploit for CVE-2024-43609, which leverages Office URI schemes to capture NTLMv2 hashes over HTTP via a 302 redirect to a UNC path. The `uncredirect.py` script facilitates this attack by redirecting HTTP requests to a Responder-controlled UNC path, enabling NTLM relay attacks.

Description

Microsoft Office Spoofing Vulnerability

Exploits (1)

github WORKING POC 146 stars
by passtheticket · htmlpoc
https://github.com/passtheticket/CVE-2024-38200

The repository contains a functional exploit for CVE-2024-43609, which leverages Office URI schemes to capture NTLMv2 hashes over HTTP via a 302 redirect to a UNC path. The `uncredirect.py` script facilitates this attack by redirecting HTTP requests to a Responder-controlled UNC path, enabling NTLM relay attacks.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office 2019, Microsoft 365
No auth needed
Prerequisites: Responder or similar tool for capturing NTLM hashes · Victim interaction to open a malicious Office URI
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
Patch, Vendor Advisory vendor-advisory patch
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43609

Scores

CVSS v3 6.5
EPSS 0.0204
EPSS Percentile 78.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (10)
microsoft/365_apps
Microsoft/Microsoft 365 Apps for Enterprise 16.0.1 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office 2016 16.0.0 - 16.0.5469.1001
Microsoft/Microsoft Office 2019 19.0.0 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office LTSC 2021 16.0.1 - https://aka.ms/OfficeSecurityReleases
Microsoft/Microsoft Office LTSC 2024 1.0.0 - https://aka.ms/OfficeSecurityReleases
microsoft/office 2016 (2 CPE variants)
microsoft/office 2019 (2 CPE variants)
microsoft/office_long_term_servicing_channel 2021 (2 CPE variants)
microsoft/office_long_term_servicing_channel 2024 (2 CPE variants)
Published Oct 08, 2024
Tracked Since Feb 18, 2026