Security News > 2023 > March > Critical Microsoft Outlook bug PoC shows how easy it is to exploit

Security researchers have shared technical details for exploiting a critical Microsoft Outlook vulnerability for Windows that allows hackers to remotely steal hashed passwords by simply receiving an email.
The issue is a privilege escalation vulnerability with a 9.8 severity rating that affects all versions of Microsoft Outlook on Windows.
"The connection to the remote SMB server sends the user's NTLM negotiation message, which the attacker can then relay for authentication against other systems that support NTLM authentication" - Microsoft.
After reviewing a script from Microsoft that checks Exchange messaging items for signs of exploitation using CVE-2023-23397, MDSec's red team member Dominic Chell discovered how easily a threat actor could leverage the bug.
The researcher also discovered that the PidLidReminderOverride property could be used to make Microsoft Outlook parse a remote, malicious UNC path in the PidLidReminderFileParameter property.
Apart from calendar appointments, an attacker could also use Microsoft Outlook Tasks, Notes, or email messages to steal the hashes.
News URL
Related news
- Researchers release PoC exploit for critical Windows CryptoAPI bug (CVE-2022-34689) (source)
- PoC exploit for recently patched Microsoft Word RCE is public (CVE-2023-21716) (source)
- Microsoft 365 outage takes down Teams, Exchange Online, Outlook (source)
- Exploit released for critical Windows CryptoAPI spoofing bug (source)
- Researchers Release PoC Exploit for Windows CryptoAPI Bug Discovered by NSA (source)
- Exploit released for critical VMware vRealize RCE vulnerability (source)
- Microsoft Outlook outage prevents users from sending, receiving emails (source)
- Fortinet plugs critical security hole in FortiNAC, with a PoC incoming (CVE-2022-39952) (source)
- Microsoft Outlook flooded with spam due to broken email filters (source)
- PoC exploit, IoCs for Fortinet FortiNAC RCE released (CVE-2022-39952) (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-03-14 | CVE-2023-23397 | Authentication Bypass by Capture-replay vulnerability in Microsoft 365 Apps, Office and Outlook Microsoft Outlook Elevation of Privilege Vulnerability | 9.8 |