logo

Microsoft Outlook December updates trigger ICS security alerts

ID: 89767a19-40c3-5070-bbb5-ffe8251363cc

STIX ID: report--89767a19-40c3-5070-bbb5-ffe8251363cc

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2024-02-05

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft confirmed that December 2023 Office security updates intended to remediate CVE-2023-35636 (an Outlook information disclosure vulnerability) are causing unexpected security warning dialogs when users open locally saved .ICS calendar files; the company calls the behavior a bug, has published a temporary registry workaround (which disables hyperlink/security prompts more broadly), and plans a future fix. The underlying CVE could allow attackers to trick users into opening crafted files to steal NTLM hashes for authentication and lateral movement if unpatched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.