In response to the discovery of a critical vulnerability in Microsoft Outlook, CVE-2023-23397, actively exploited in the wild by the threat actors, Cisco Talos urges all Outlook users to update their email clients as soon as possible after the vulnerability has been discovered.
While Microsoft later determined that the activities resulted from Russian-based actors, and they were being used in targeted attacks against a limited number of organizations.
As a result of the exploitation of this security vulnerability, the attacks were conducted between mid-April and December 2022. During this time, threat actors targeted and breached the networks of about 15 critical organizations related to:-
To steal NTLM hashes, the hackers sent malicious Outlook notes and tasks to the targeted devices to force them to authenticate to the attacker-controlled SMB that shares the hashes.
The vulnerability CVE-2023-23397 affects all Microsoft Outlook products that run on the Windows operating system. It’s a vulnerability in NTLM and could be exploited for credential theft to gain affluent access to an organization through an escalation of privilege vulnerability.
Threat actors can create emails, calendar invites, or tasks that contain the extended MAPI property “PidLidReminderFileParameter.”
“PidLidReminderFileParameter” allows the client to specify the filename of the sound to be played when the reminder for an object becomes overdue.
This PidLidReminderFileParameter property is used by the attacker to specify a path to the SMB share controlled by the attacker via a Universal Naming Convention (UNC).
An attacker may be able to make use of the Net-NTLMv2 hash sent by a vulnerable system to constitute an NTLM Relay attack against another system.
As a result, Microsoft researchers have affirmed some key mitigations that organizations must follow as a precaution to keep themselves safe from this kind of cyber attack:-
Microsoft Outlook on Windows is affected by this privilege escalation vulnerability with a severity rating of 9.8, which affects all versions of the application.
By sending a malicious email to the target, an attacker can use this vulnerability to steal their NTLM credentials in a matter of seconds.
Whenever Outlook is open, the reminder will be displayed on the system, and no interaction with the user is required as the exploitation occurs automatically.
In short, it’s strongly advised by security analysts that admins must apply and check all the recommended mitigations immediately to prevent any attack effectively.
Network Security Checklist – Download Free E-Book
Related Read:
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…