Microsoft releases fix for patched Outlook issue exploited by Russian hackers
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-23397 | Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak) CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates. Do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook. | 9.8 | 97% | KEV |
| masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite) | |
| CVE-2023-24932 +1 in the same advisory: …29324 | Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability NVD description · AI analysis pending | 6.7 group max | 11% |
| — | ||
| CVE-2023-29336 | Use-after-free privilege escalation to SYSTEM in Microsoft Win32k CVE-2023-29336 is a use-after-free flaw (CWE-416) in Microsoft's Win32k kernel component that allows privilege escalation to SYSTEM. It is triggered by code running on a Windows host that causes the Win32k driver to reference freed kernel memory; the exact trigger path is not detailed in the available data, but as a kernel elevation-of-privilege issue it requires local code execution or an attacker already holding a foothold on the machine. A successful exploit grants SYSTEM privileges, giving the attacker full control of the compromised host. Because Win32k ships in every supported Windows client and server, effectively the entire Windows installed base is exposed to the flaw. The vulnerability is confirmed exploited in the wild — CISA added it to the KEV catalog on 2023-05-09 — and EPSS places its 30-day exploitation probability at 40.9% (99th percentile), though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Apply Microsoft's current cumulative Windows security updates (issued May 2023, per the CISA KEV required action) across all Windows clients and servers, prioritizing servers and systems exposed to untrusted users since the flaw is being actively exploited. Until patched, limit untrusted local code execution and restrict remote entry points such as RDP, because local privilege escalation flaws are commonly chained into full compromises. Verify update installation after deployment; specific affected build numbers and any ransomware involvement are not stated in the available data. | 7.8 | 41% | KEV PoC |
| mass≈1 billion+ Windows devices (Win32k ships in every supported Windows client and server) |
Full article619 words · extracted from therecord.media · click to collapse
Microsoft on Tuesday released a new fix for a vulnerability that was initially patched in March but was later discovered by security researchers to be flawed. Ukrainian cybersecurity officials at CERT-UA reported a vulnerability to the Microsoft incident response team earlier this year after Russia-based hackers used a vulnerability in Microsoft’s Outlook email service. “Microsoft Threat Intelligence assesses that a Russia-based threat actor used the exploit patched in CVE-2023-23397 in targeted attacks against a limited number of organizations in government, transportation, energy, and military sectors in Europe,” Microsoft said in an advisory, noting that it had a CVSS score of 9.8 out of 10. Although the issue was patched in March, Akamai researcher Ben Barnea discovered a way around the patch that would allow an attacker to use the vulnerability to coerce an Outlook client to connect to an attacker-controlled server. Barnea said the issue is a zero-click vulnerability – meaning it can be triggered with no user interaction – and all Windows versions are affected by it. Remember that 0-click Outlook vulnerability with a custom sound leading to NTLM theft? Akamai researchers found a way to bypass the patch to it. In our write-up, see how adding a slash allowed for a bypass.https://t.co/eO121SaZur pic.twitter.com/YrrBikMZqj The issue was reported to Microsoft and fixed on Tuesday, and is referred to as CVE-2023-29324. Barnea explained that the addition of a single character rendered the initial patch useless. But he and the security team at Akamai took issue with Microsoft’s classification of the issue, which was given a CVSS score of just 6.5. “According to information shared with us, by Microsoft, beforehand (and seemingly with others as well), the vulnerability indeed received critical severity and a CVSS score of 7.5. However, on Patch Tuesday Microsoft ranked the vulnerability as important and reduced its CVSS to 6.5,” they said. “Our research indicates that the new vulnerability re-enables the exploitation of a critical vulnerability that was seen in the wild and used by APT [advanced persistent threat] operators. We still believe our finding is of high severity. In the hands of a malicious actor, it could still have the same consequences as the critical original Outlook bug.” Microsoft did not respond to questions about the discrepancy, only telling Recorded Future News that “customers who apply the update, or have automatic updates enabled, will be protected.” A spokesperson also shared a link to the initial advisory from March, which has been updated with an acknowledgement of Akamai’s findings. The vulnerability allowed for the theft of credentials related to Windows New Technology LAN Manager (NTLM) – a suite of security protocols offered by Microsoft to authenticate users' identity and protect the integrity and confidentiality of their activity. Barnea said the vulnerability is “yet another example of patch scrutinizing leading to new vulnerabilities and bypasses.” “Specifically for this vulnerability, the addition of one character allows for a critical patch bypass,” he said. “Considering how ubiquitous Windows is, eliminating an attack surface as ripe as this is could have some very positive effects.” On Patch Tuesday, Microsoft fixed 49 other vulnerabilities, including three zero-day vulnerabilities and five critical Remote Code Execution (RCE) vulnerabilities. Two of the actively exploited zero-day vulnerabilities – CVE-2023-29336 and CVE-2023-24932 – were allegedly exploited by Turla, a group long affiliated with the Russian Federal Security Service (FSB).
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-releases-fix-for-patched-outlook-bug-russian-hackers