logo

Microsoft fixes Outlook security alerts bug caused by December updates

ID: 9320a94a-a6bd-5006-8cae-43ceff54f733

STIX ID: report--9320a94a-a6bd-5006-8cae-43ceff54f733

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2024-04-04

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft fixed an Outlook information-disclosure vulnerability (CVE-2023-35636) that could allow attackers to steal NTLM hashes via malicious .ICS calendar files; the patch is being rolled out to Microsoft 365 Beta/Insider channels with broader deployment planned, and a registry-based workaround is available until the fix reaches all users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.