Critical Outlook Vulnerability: In-Depth Technical…
ID: 43f3ce2b-a7f9-5738-b256-7c781a114055
STIX ID: report--43f3ce2b-a7f9-5738-b256-7c781a114055
Feed Name: TrustedSec blog
Threat Score
**Executive Summary:** CVE-2023-23397 is a critical Outlook vulnerability actively exploited in the wild—reportedly by a Russian military-linked group—that enables theft of NTLM credentials via specially crafted calendar/meeting invites that trigger an automatic SMB/WebDAV authentication to attacker-controlled shares; the report includes PoC PowerShell, detection (Sigma) guidance, and mitigation recommendations including blocking outbound SMB (445) and applying Microsoft patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
