Cyber Security News

Russian Hackers Actively Exploiting Outlook Privilege Escalation Vulnerability

Hackers target and exploit Outlook vulnerabilities because it is a widely used email platform, providing a large potential victim pool. 

Exploiting vulnerabilities in Outlook allows hackers to:-

  • Gain unauthorized access to sensitive information
  • Compromise systems
  • Execute malicious activities

Cybersecurity researchers at Microsoft recently identified that Forest Blizzard (STRONTIUM), a Russian nation-state group, is actively exploiting the “CVE-2023-23397” for unauthorized access to Exchange server email accounts. 

In collaboration with the Polish Cyber Command (DKWOC), Microsoft takes action against the threat actors behind this Russian nation-state group, Forest Blizzard.

Outlook Privilege Escalation Vulnerability

CVE-2023-23397 is marked as a critical Outlook vulnerability on Windows, and it’s a privilege escalation vulnerability that allows threat actors to exploit a crafted message triggering Net-NTLMv2 hash leak to their controlled server.

This critical privilege escalation vulnerability has affected all the Outlook versions on Windows, but it didn’t affect any version of the following platforms:-

  • Android
  • iOS
  • Mac
  • Web (OWA)

Utilizing Microsoft’s TNEF (Transport Neutral Encapsulation Format), this technique employs Winmail.dat attachments to transmit formatted email messages, including attachments and Outlook-specific features.

Outlook on Windows allows users to set custom reminder sounds, affecting the PidLidReminderFileParameter MAPI property.

Setting a custom sound (Source – Microsoft)

Threat actors exploit this, using tools like MFCMAPI to manipulate properties, deceive users, and leak the Net-NTLMv2 hash of the signed-in Windows user.

Here below, we have mentioned all the post-exploitation actions:-

  • Initial access (authentication bypass): Exchange Servers vulnerable to Net-NTLMv2 Relay attack. The notable thing is that Azure AD, default for Exchange Online, is not directly susceptible, but a federated identity provider may be at risk.
  • Credential access/lateral movement: In exploiting Exchange Web Services (EWS) API, threat actors send malicious PidLidReminderFileParameter values to internal and external users.
  • Discovery/persistence: Exploiting EWS API, threat actors enumerate and alter folder permissions in a compromised user’s mailbox, granting unauthorized access. This persistence method ensures continued access even after password resets.

Recommendations

Here below, we have mentioned all the recommendations provided by the cybersecurity researchers:-

  • Make sure to update Microsoft Outlook promptly for mitigation. Implement recommended security practices to mitigate the threat if immediate patching is not feasible.
  • Apply the latest security updates for on-premises Microsoft Exchange Server to activate defense-in-depth mitigations.
  • If suspicious reminder values are detected, use the script to remove messages or properties and initiate incident response as needed.
  • Reset passwords for targeted users who received suspicious reminders and initiate an incident response for affected accounts.
  • Mitigate the impact of Net-NTLMv2 Relay attacks with the implementation of multifactor authentication.
  • Make sure that all the unnecessary services are disabled on Exchange.
  • Control SMB traffic by blocking ports 135 and 445, allowing only specified IP addresses on the allowlist.
  • In your environment, disable NTLM.
Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago