Microsoft Outlook Privilege Elevation Critical Vulnerability
ID: fff6218b-fb4e-5a17-8771-e1deca412325
STIX ID: report--fff6218b-fb4e-5a17-8771-e1deca412325
Feed Name: Kudelski Security
**CVE-2023-23397 (Outlook NTLM relay zero-day)**: An actively exploited Outlook vulnerability allows specially crafted emails to force Outlook clients to authenticate to attacker-controlled UNC shares, exposing Net-NTLMv2 hashes that can be relayed for unauthorized access; activity has been attributed to APT28 and affects multiple Outlook/Office versions. The report summarizes technical details (abuse of PidLidReminderFileParameter/PidLidReminderOverride properties), potential post-exploitation impacts (credential theft, lateral movement, persistence), and recommended mitigations including patching, disabling WebClient, blocking outbound SMB (TCP/445), using the Protected Users group, and running Microsoft's Exchange audit/cleanup PowerShell script.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
