logo

Three new Zero-Day CVE disclosed

ID: 5a1b74a0-1d09-5692-b528-4275548d93e5

STIX ID: report--5a1b74a0-1d09-5692-b528-4275548d93e5

Feed Name: ThreatLocker Blog

Threat Score
75/100

Date Published: 2025-05-21

Date Updated: 2026-05-01

...
...

**Executive Summary:** Microsoft disclosed three critical zero-day vulnerabilities—CVE-2023-41763 (Skype for Business information disclosure), CVE-2023-36563 (OLE/NTLM hash disclosure enabling offline credential cracking), and CVE-2023-44487 (HTTP/2 rapid-reset DoS)—and the report outlines how an attacker could chain them to map internal services, harvest credentials, and launch internal DoS attacks; it also lists Microsoft patches, workarounds, and ThreatLocker-specific mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.