logo

Microsoft finally fixes Outlook alerts bug caused by December updates

ID: a334ea0f-518f-5b6d-b798-b94ebd41b3ea

STIX ID: report--a334ea0f-518f-5b6d-b798-b94ebd41b3ea

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2024-07-16

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

Microsoft addressed an Outlook Desktop vulnerability (CVE-2023-35636) that caused incorrect security alerts and could allow malicious ICS files to exfiltrate NTLM hashes for pass-the-hash attacks; the patch was tested, rolled back briefly in Insider channels, and ultimately released to the public on July 9, with Microsoft advising customers to revert temporary registry workarounds before applying the fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.