Microsoft Outlook December updates trigger ICS security alerts
ID: 89767a19-40c3-5070-bbb5-ffe8251363cc
STIX ID: report--89767a19-40c3-5070-bbb5-ffe8251363cc
Feed Name: Bleeping Computer
Microsoft confirmed that December 2023 Office security updates intended to remediate CVE-2023-35636 (an Outlook information disclosure vulnerability) are causing unexpected security warning dialogs when users open locally saved .ICS calendar files; the company calls the behavior a bug, has published a temporary registry workaround (which disables hyperlink/security prompts more broadly), and plans a future fix. The underlying CVE could allow attackers to trick users into opening crafted files to steal NTLM hashes for authentication and lateral movement if unpatched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
