Microsoft finally fixes Outlook alerts bug caused by December updates
ID: a334ea0f-518f-5b6d-b798-b94ebd41b3ea
STIX ID: report--a334ea0f-518f-5b6d-b798-b94ebd41b3ea
Feed Name: Bleeping Computer
Threat Score
Microsoft addressed an Outlook Desktop vulnerability (CVE-2023-35636) that caused incorrect security alerts and could allow malicious ICS files to exfiltrate NTLM hashes for pass-the-hash attacks; the patch was tested, rolled back briefly in Insider channels, and ultimately released to the public on July 9, with Microsoft advising customers to revert temporary registry workarounds before applying the fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
