Cybersecurity in the news: Understanding Microsoft Outlook vulnerability, CVE-2023-23397, mitigation strategies
ID: fc2c81d9-98ee-5ab4-a2b5-36c456757382
STIX ID: report--fc2c81d9-98ee-5ab4-a2b5-36c456757382
Feed Name: ThreatLocker Blog
Threat Score
CVE-2023-23397 is a critical Outlook-for-Windows vulnerability where a specially crafted calendar invite embeds a UNC path in the reminder sound parameter, causing Outlook to automatically connect to an attacker-controlled SMB server and exposing the user's NTLM hash and username; mitigations include applying Microsoft patches, blocking outbound SMB (port 445), using Protected Users group, and employing endpoint controls such as ThreatLocker ringfencing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
