Kremlin-backed hackers attacking unpatched Outlook systems, Microsoft says
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-23397 | Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak) CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates. Do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook. | 9.8 | 97% | KEV |
| masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite) |
Full article451 words · extracted from therecord.media · click to collapse
Hackers associated with Russia’s military intelligence are still actively exploiting a vulnerability in Microsoft software to gain access to victims’ emails, the company said Monday. The threat actor, tracked by Microsoft as Forest Blizzard but also known as Fancy Bear or APT28, has been attempting to use the bug to gain unauthorized access to email accounts within Microsoft Exchange servers since as early as April 2022, researchers said in an update to a report from March. The vulnerability is tracked as CVE-2023-23397, and it affects all versions of Microsoft Outlook software on Windows devices. Microsoft patched the flaw in the spring after Russian hackers exploited it in attacks "against a limited number of organizations in government, transportation, energy, and military sectors in Europe." “Users should ensure Microsoft Outlook is patched and kept up to date to mitigate this threat,” the researchers said. Successful exploitation allows hackers to access victims’ email correspondence, according to the Polish Cyber Command, which partnered with Microsoft to investigate the attacks. In the cases investigated by the Polish cybersecurity agency, hackers exploited the Outlook vulnerability to gain access to mailboxes containing “high-value information.” An attack begins when a threat actor delivers a specially crafted message to a user, according to Microsoft. The user does not even need to interact with this message if Outlook on their Windows device is open. Exploitation of the flaw leaves very few forensic traces, making it hard to detect hacker activity. Fancy Bear, labeled by cybersecurity researchers as an advanced persistent threat (APT) group, primarily targets government, energy, transportation, and nongovernmental organizations in the U.S., Europe, and the Middle East. The group is linked to Russia’s military intelligence agency (GRU). In October, France accused the group of targeting universities, businesses, think tanks and government agencies. In September, it attempted to attack a critical energy facility in Ukraine. The hackers commonly exploit publicly available vulnerabilities. In addition to the Microsoft Outlook flaw, they also targeted a popular file archiver utility for Windows called WinRAR “to adapt spear-phishing operations against chiefly Ukrainian government targets. According to Microsoft, the group is “well-resourced and well-trained,” which poses “long-term challenges to attribution and tracking its activities.” Poland's Cyber Command said that the group possesses a high level of sophistication and in-depth knowledge of the architecture and mechanisms of the Microsoft Exchange mail system.Familiar APT
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/unpatched-microsoft-outlook-email-attacks-fancy-bear