Bleak outlook: Mitigating CVE-2023-23397
ID: 23718405-e093-5239-9a08-55845927fb82
STIX ID: report--23718405-e093-5239-9a08-55845927fb82
Feed Name: Group-IB Blog
Critical Microsoft Outlook for Windows vulnerability CVE-2023-23397 (CVSS 9.8) is being actively exploited in targeted attacks: a specially crafted email using the PidLidReminderFileParameter forces the client to connect to an attacker-controlled SMB share and emits an NTLM negotiate message that can be relayed for unauthorized access without any user interaction. Attribution points to a Russia-based nation-state actor (APT28) targeting European government, transportation, energy, and military organizations; mitigations include applying Microsoft patches, blocking outbound TCP/445, and using the Protected Users security group, while indicators and PoC exploit code are publicly available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
