Microsoft fixes Outlook security alerts bug caused by December updates
ID: 9320a94a-a6bd-5006-8cae-43ceff54f733
STIX ID: report--9320a94a-a6bd-5006-8cae-43ceff54f733
Feed Name: Bleeping Computer
Threat Score
Microsoft fixed an Outlook information-disclosure vulnerability (CVE-2023-35636) that could allow attackers to steal NTLM hashes via malicious .ICS calendar files; the patch is being rolled out to Microsoft 365 Beta/Insider channels with broader deployment planned, and a registry-based workaround is available until the fix reaches all users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
