Threat alert details
We would like to bring your attention to a critical vulnerability within Microsoft Outlook which allows for elevation of privileges with a CVSS3 score of 9.8. This vulnerability allows specially crafted emails to force a target’s device to connect to a remote URL and transmit the Windows user account’s Net-NTLMv2 hash. This exploit can grant unauthenticated attackers access to the target user’s Net-NTLMv2 hash, which can then be used to launch further attacks against another service in order to authenticate as the compromised user.
Further details will be provided as More information becomes available.
Affected Versions
This vulnerability has been reported to impact all supported versions of Microsoft Outlook for Windows however does not appear to affect Outlook for Android, iOS, or macOS versions of Outlook
Indicators of compromise
Microsoft have released a Powershell script to aid in investigations for potential compromise from this vulnerability. The script is available from the following URL and can be used in an audit only capacity or in a cleanup mode:
https://microsoft.github.io/CSS-Exchange/Security/CVE-2023-23397/
Remediation
In this weeks Patch Tuesday Microsoft has released a critical security update for Microsoft Outlook. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397
References
- https://techcommunity.microsoft.com/t5/exchange-team-blog/released-march-2023-exchange-server-security-updates/ba-p/3764224#:~:text=under%20Product%20Family).-,Awareness%3A%20Outlook%20client%20update%20for%20CVE%2D2023%2D23397%20released,-There%20is%20a
- https://microsoft.github.io/CSS-Exchange/Security/CVE-2023-23397/
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397
More like this
![](https://www.covertswarm.com/wp-content/uploads/2024/06/2024-Academy-Intake-3-640x320.png)
Academy Launches Second Intake
CovertSwarm’s Academy is opening the 2024 intake. Apply and start your cybersecurity journey as an ethical hacker.
![DORA & NIS2 European Flag](https://www.covertswarm.com/wp-content/uploads/2024/05/DORA-and-NIS2-European-Flag-640x320.png)
Combining regulation with real-world security assurance: DORA and NIS2
Whether you’re a local financial startup or a multinational food distributor, understanding how DORA and NIS2 may affect your organization is vital. With implementation dates just…
![](https://www.covertswarm.com/wp-content/uploads/2024/05/Clutch-100-fastest-growth-640x320.png)
CovertSwarm named by Clutch among Top 100 Fastest-Growing Companies
Clutch has recognized us for achieving one of the highest revenue growth rates from 2022 to 2023.