March 15, 2025Try Cyber is a web application for cyber work role discovery and exploration. It provides the cyber curious free access to short 15-minute hands-on micro-challenges, where participants can experience a day-one internship as one of the ten supported NICE...
Microsoft Urgent Outlook Vulnerability Notice
Microsoft Urgent Outlook Vulnerability Notice
March 17, 2023
On 3/14/23 Microsoft released patches to address a critical vulnerability found in Microsoft Outlook for Windows. This vulnerability affects only Microsoft Outlook for Windows. Other versions such as those for Android, iOS, Mac, and Outlook/M365 on the web are not affected.
CVE-2023-23397
Microsoft Outlook Elevation of Privilege (EoP) Vulnerability
CVSSv3.1: 9.8
This vulnerability may be triggered by an attacker that sends a crafted, expired appointment to a user. This will activate the reminder feature within Outlook for overdue appointments with no user interaction required.
The attacker-crafted appointment will exploit the path to the sound file that Outlook plays for a reminder when it is overdue, substituting a UNC (Universal Naming Convention) path within the message that leads to their own server. This will cause the Outlook client to send the user’s login name and their NTLM password hash to the attacker’s remote server.
This exploit does NOT require the recipient to interact with the appointment received from the attacker. The message will be processed behind the scenes, potentially leaving the user unaware that they have been compromised.
Mitigations
- Ensure current patches are applied.
- For those that cannot patch right away, Microsoft provides guidance for DCs using Windows 2012 R2 or newer. Consider adding on-premises accounts to a Protected Users Security Group. This prevents the use of NTLM as an authentication method by group members and continues to allow legacy applications that require NTLM to be excluded from the group and still utilize that authentication method. (Ensure that you review Microsoft documentation for Protected Users Security Groups before implementing: https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/protected-users-security-group?WT.mc_id=M365-MVP-9501 )
Detection and Response
- Microsoft has made a script available that will review the Exchange environment to see whether a property is populated for a UNC path. The script can also be used to clean up the property for the malicious appointment reminders or even delete the items permanently.
- https://microsoft.github.io/CSS-Exchange/Security/CVE-2023-23397/
Additional Resources
Try Cyber
PISCES Technical Advisory Chair publishes new analyst book
October 15, 2024The architect of the PISCES International cyber analyst curriculum Michael Tsikerdekis has published a book on taking you from zero to hero (no prerequisites) to ultimately become a security analyst. There are a bunch of illustrations to reduce the...
Spokane Falls Cyber Center trains future workforce through industry partnership
July 23, 2024(This article was originally published on SFCC) [SPOKANE, Wash.] — Kory Bruno grew up playing computer games where he could be one destroying data and hacking networks. Now the Spokane Falls Community College alumni spends every day doing top secret work...