Microsoft pulls fix for Outlook bug behind ICS security alerts
ID: 0d33abb7-229a-5dcd-995a-557f24e41987
STIX ID: report--0d33abb7-229a-5dcd-995a-557f24e41987
Feed Name: Bleeping Computer
Microsoft rolled back an Outlook fix that was causing incorrect "Microsoft Office has identified a potential security concern" warnings when opening ICS files after December security updates. The December updates had addressed CVE-2023-35636 (an information-disclosure vulnerability that could expose NTLM hashes and enable pass-the-hash attacks). Microsoft disabled the new fix pending modifications; a registry workaround exists but it also disables security prompts for other file types, reducing protections for users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
