ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Patches Two Zero Days This Month

criticalVulnerability exploited in the wildimportance 60CVE-2023-23397CVE-2023-24880CVE-2023-21708

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-21708
Remote Procedure Call Runtime Remote Code Execution Vulnerability

Remote Procedure Call Runtime Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.81%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2023-23397
Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak)

CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates.

Do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook.

9.897% KEV
  • Microsoft 365 Apps Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Long Term Servicing Channel (LTSC) Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • +1 more
masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite)
CVE-2023-24880
SmartScreen Security Feature Bypass in Windows 10/11 and Windows Server

CVE-2023-24880 is a security feature bypass (incorrect authorization, CWE-863) in Windows SmartScreen: when a user opens a file carrying Mark-of-the-Web — such as an email attachment or a downloaded file — Windows fails to display the SmartScreen 'Open File – Security Warning' prompt that normally precedes execution. An attacker who can get a user to open a crafted malicious file therefore gains the ability to run attacker-chosen code on that machine without the SmartScreen warning, defeating a core client-side defense; the bypass was typically chained with a lure or another flaw to deliver malware, including loaders feeding ransomware operations. Any user or organization running the affected Windows 10, Windows 11, or Windows Server builds is affected, though exploitation requires local access and user interaction (CVSS 4.4, local attack vector). The flaw was a zero-day exploited in the wild before Microsoft patched it in the March 2023 Patch Tuesday release — one of two actively exploited flaws fixed that month — and Google researchers reported a ransomware gang exploited it; CISA added it to the Known Exploited Vulnerabilities Catalog on 2023-03-14 with known ransomware use, and EPSS rates the probability of exploitation within 30 days at 78.2% (100th percentile). No public proof-of-concept is known, but confirmed in-the-wild exploitation means defenders should treat it as actively targeted.

Do: Apply the March 2023 Windows security updates to all affected Windows 10 (1607, 1809, 20H2, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2016/2019/2022 systems via Windows Update, WSUS, or your patch-management tooling, and verify coverage in your inventory — this is CISA's required action for KEV. Until patched, treat any host whose users open untrusted email attachments or downloads as exposed, since the bypass silently skips the SmartScreen warning; updating is the only complete fix, with no published configuration workaround.

4.478% KEV ransomware
  • microsoft Windows 10 1607, 1809, 20H2, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2
  • microsoft Windows Server 2016, 2019, 2022
masshundreds of millions of Windows endpoints and servers
Full article359 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft has fixed over 80 vulnerabilities in this month’s Patch Tuesday update round, including two zero days being actively exploited in the wild.

One of those is CVE-2023-23397, a critical elevation of privilege bug in Outlook with a CVSS score of 9.8.

“The attack can be executed without any user interaction by sending a specially crafted email which triggers automatically when retrieved by the email server. This can lead to exploitation before the email is even viewed in the Preview Pane,” explained Action1 VP of vulnerability and threat research, Mike Walters.

“If exploited successfully, an attacker can access a user’s Net-NTLMv2 hash, which can be used to execute a pass-the-hash attack on another service and authenticate as the user.”

The bug was reported by the Computer Emergency Response Team for Ukraine (CERT-UA), hinting that it was being actively exploited by Russian threat actors.

Read more about Russia’s cyber-offensive in Ukraine: Microsoft: Russia Has Launched Hundreds of Cyber Operations in Ukraine

The second zero day, CVE-2023-24880, is a security feature bypass in Windows SmartScreen.

It enables attackers to craft a malicious file capable of circumventing Mark-of-the-Web (MOTW) defenses in features like Protected View in Office, according to Microsoft.

“This CVE affects all currently supported versions of the Windows OS,” explained Ivanti VP of security products, Chris Goettl. “The CVSS score is only 5.4, which may avoid notice by many organizations and on its own this CVE may not be all that threatening, but it was likely used in an attack chain with additional exploits. Prioritizing this month’s OS update would reduce the risk to your organization.”

Of the nine critical CVEs listed this month, CVE-2023-21708 should also be a priority for security teams, argued Gal Sadeh, head of data and security research at Silverfort. It refers to a remote code execution bug in Remote Procedure Call Runtime that allows unauthenticated attackers to run remote commands on a target machine.

“Threat actors could use this to attack domain controllers, which are open by default,” he added. “To mitigate, we recommend domain controllers only allow RPC from authorized networks and RPC traffic to unnecessary endpoints and servers is limited.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-patches-two-zero-days/