logo

Microsoft discloses unpatched Office flaw that exposes NTLM hashes

ID: 1af5ac5f-16b5-54a1-9a48-720d985feb5b

STIX ID: report--1af5ac5f-16b5-54a1-9a48-720d985feb5b

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-08-09

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft disclosed CVE-2024-38200, an information-disclosure vulnerability in Office 2016, Office 2019, Office LTSC 2021, and Microsoft 365 Apps that can be abused to force outbound NTLM authentication and leak NTLM hashes; Microsoft applied an interim fix via Feature Flighting on 2024-07-30 and advises applying the August 13, 2024 updates or mitigating by blocking outbound NTLM traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.