logo

Microsoft pulls fix for Outlook bug behind ICS security alerts

ID: 0d33abb7-229a-5dcd-995a-557f24e41987

STIX ID: report--0d33abb7-229a-5dcd-995a-557f24e41987

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2024-04-23

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft rolled back an Outlook fix that was causing incorrect "Microsoft Office has identified a potential security concern" warnings when opening ICS files after December security updates. The December updates had addressed CVE-2023-35636 (an information-disclosure vulnerability that could expose NTLM hashes and enable pass-the-hash attacks). Microsoft disabled the new fix pending modifications; a registry workaround exists but it also disables security prompts for other file types, reducing protections for users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.