ZeroHour
The Recordpublished ()ingested

More evidence of Russian intelligence exploiting old Outlook flaw

criticalData breachimportance 60CVE-2023-23397

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-23397
Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak)

CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates.

Do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook.

9.897% KEV
  • Microsoft 365 Apps Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Long Term Servicing Channel (LTSC) Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • +1 more
masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite)
Full article275 words · extracted from therecord.media · click to collapse

Cybersecurity researchers have discovered another campaign in which hackers associated with Russia’s military intelligence are exploiting a vulnerability in Microsoft software to target critical entities, including those in NATO member countries.

According to a report by Palo Alto Networks' Unit 42, the Russian threat actor known as Fancy Bear or APT28 breached Microsoft Outlook over the past two years to spy on at least 30 organizations within 14 nations “that are likely of strategic intelligence value to the Russian government and its military.”

Tracked as CVE-2023-23397, the flaw in Outlook allows hackers to gain unauthorized access to email accounts within Microsoft Exchange servers. Microsoft patched the flaw in the spring.

In the most recent campaign, analyzed by Unit 42 in September and October of this year, the group targeted organizations within NATO member countries as well as entities in Ukraine, Jordan, and the United Arab Emirates.

The targets include ministries, defense and energy facilities, and transportation and telecommunication companies, researchers said. Attackers also aimed for at least one NATO Rapid Deployable Corps, the alliance’s high-readiness commands.

This is the third report this week about Russian hackers exploiting the Microsoft Outlook flaw. The others:

  • Microsoft and the Polish cybersecurity agency published joint research claiming that Fancy Bear exploited the Outlook vulnerability to gain access to unspecified mailboxes containing "high-value information."
  • Proofpoint published a separate report, stating that it observed phishing activity in which APT28 used the Outlook bug in high-volume campaigns to target entities in Europe and North America.

Researchers are urging high-risk organizations to be vigilant about patching Outlook, especially because the Russian hackers continue to exploit CVE-2023-23397 despite the publicity it has received.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-outlook-vulnerability-apt28-hackers-russia-nato