Everything We Know About CVE-2023-23397
ID: 0fdda181-d47f-501a-81e7-997beb536bdc
STIX ID: report--0fdda181-d47f-501a-81e7-997beb536bdc
Feed Name: Huntress Blog
Huntress documents active exploitation of CVE-2023-23397, a critical Outlook vulnerability that allows zero-interaction theft of Net-NTLMv2 hashes via crafted calendar invites using specific MAPI properties; attackers can force Outlook to reach out to remote UNC/WebDAV resources (triggering NTLM authentication) enabling credential capture and lateral movement—Huntress provides detection artifacts (svchost.exe → rundll32.exe invoking davclnt.dll with a remote UNC/.WAV), mitigation guidance (apply Microsoft's patches immediately, disable reminders as a temporary mitigation, consider blocking outbound SMB or using Protected Users), and hunting resources from Microsoft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
