ZeroHour
Security Affairspublished ()ingested @securityaffairs1

Microsoft Patch Tuesday fix Outlook zero

criticalVulnerability exploited in the wildimportance 60CVE-2023-23397CVE-2023-24880

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-23397
Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak)

CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates.

Do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook.

9.897% KEV
  • Microsoft 365 Apps Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Long Term Servicing Channel (LTSC) Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • +1 more
masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite)
CVE-2023-24880
SmartScreen Security Feature Bypass in Windows 10/11 and Windows Server

CVE-2023-24880 is a security feature bypass (incorrect authorization, CWE-863) in Windows SmartScreen: when a user opens a file carrying Mark-of-the-Web — such as an email attachment or a downloaded file — Windows fails to display the SmartScreen 'Open File – Security Warning' prompt that normally precedes execution. An attacker who can get a user to open a crafted malicious file therefore gains the ability to run attacker-chosen code on that machine without the SmartScreen warning, defeating a core client-side defense; the bypass was typically chained with a lure or another flaw to deliver malware, including loaders feeding ransomware operations. Any user or organization running the affected Windows 10, Windows 11, or Windows Server builds is affected, though exploitation requires local access and user interaction (CVSS 4.4, local attack vector). The flaw was a zero-day exploited in the wild before Microsoft patched it in the March 2023 Patch Tuesday release — one of two actively exploited flaws fixed that month — and Google researchers reported a ransomware gang exploited it; CISA added it to the Known Exploited Vulnerabilities Catalog on 2023-03-14 with known ransomware use, and EPSS rates the probability of exploitation within 30 days at 78.2% (100th percentile). No public proof-of-concept is known, but confirmed in-the-wild exploitation means defenders should treat it as actively targeted.

Do: Apply the March 2023 Windows security updates to all affected Windows 10 (1607, 1809, 20H2, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2016/2019/2022 systems via Windows Update, WSUS, or your patch-management tooling, and verify coverage in your inventory — this is CISA's required action for KEV. Until patched, treat any host whose users open untrusted email attachments or downloads as exposed, since the bypass silently skips the SmartScreen warning; updating is the only complete fix, with no published configuration workaround.

4.478% KEV ransomware
  • microsoft Windows 10 1607, 1809, 20H2, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2
  • microsoft Windows Server 2016, 2019, 2022
masshundreds of millions of Windows endpoints and servers
Full article429 words · extracted from securityaffairs.com · click to collapse

Microsoft Patch Tuesday updates for March 2023 addressed 74 vulnerabilities, including a Windows zero-day exploited in ransomware attacks.

Microsoft Patch Tuesday security updates for March 2023 addressed 74 new vulnerabilities in Microsoft Windows and Windows Components; Office and Office Components; Edge (Chromium-based); Microsoft Dynamics; Visual Studio; and Azure.

Six of the fixed issues are rated Critical and 67 are rated Important, while only one is rated Moderate in severity.

Two of the vulnerabilities addressed by the IT giant, respectively tracked as CVE-2023-23397 and CVE-2023-24880, are actively exploited in the wild.

The CVE-2023-23397 flaw is a Microsoft Outlook spoofing vulnerability that can lead to an authentication bypass.

A remote, unauthenticated attacker can exploit the flaw to access a user’s Net-NTLMv2 hash by sending a specially crafted e-mail to an affected system.

“An attacker who successfully exploited this vulnerability could access a user’s Net-NTLMv2 hash which could be used as a basis of an NTLM Relay attack against another service to authenticate as the user.” reads the advisory published by Microsoft.

“The attacker could exploit this vulnerability by sending a specially crafted email which triggers automatically when it is retrieved and processed by the Outlook client. This could lead to exploitation BEFORE the email is viewed in the Preview Pane.” “External attackers could send specially crafted emails that will cause a connection from the victim to an external UNC location of attackers’ control. This will leak the Net-NTLMv2 hash of the victim to the attacker who can then relay this to another service and authenticate as the victim.”

The vulnerability was reported by the CERT-UA and the Microsoft Incident Response, Microsoft Threat Intelligence (MSTI), suggesting that it has been exploited by a nation-state actor.

The second flaw actively exploited in the wild is a Windows SmartScreen security feature bypass vulnerability tracked as CVE-2023-24880.

An attacker can exploit the vulnerability to bypass Mark of the Web (MOTW) defenses by using specially crafted files. Microsoft Office SmartScreen and Protected View defense features rely on MOTW, this means that the flaw can be exploited to bypass them and deliver malware via crafted documents.

“An attacker can craft a malicious file that would evade Mark of the Web (MOTW) defenses, resulting in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.” states Microsoft.

This second flaw has been exploited by attackers to bypass the Windows SmartScreen and deploy the Magniber ransomware.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft Patch Tuesday)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/143486/security/microsoft-patch-tuesday-march-2023.html