Three new Zero-Day CVE disclosed
ID: 5a1b74a0-1d09-5692-b528-4275548d93e5
STIX ID: report--5a1b74a0-1d09-5692-b528-4275548d93e5
Feed Name: ThreatLocker Blog
**Executive Summary:** Microsoft disclosed three critical zero-day vulnerabilities—CVE-2023-41763 (Skype for Business information disclosure), CVE-2023-36563 (OLE/NTLM hash disclosure enabling offline credential cracking), and CVE-2023-44487 (HTTP/2 rapid-reset DoS)—and the report outlines how an attacker could chain them to map internal services, harvest credentials, and launch internal DoS attacks; it also lists Microsoft patches, workarounds, and ThreatLocker-specific mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
