logo

Beware: Experts Reveal New Details on Zero-Click Outlook RCE Exploits

ID: 233bb80e-5873-554b-9d57-0e09efc7b4eb

STIX ID: report--233bb80e-5873-554b-9d57-0e09efc7b4eb

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2023-12-18

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Akamai disclosed technical details for two now-patched Windows flaws—CVE-2023-35384 (MSHTML security zone bypass) and CVE-2023-36710 (Audio Compression Manager integer overflow)—which can be chained to achieve zero-click remote code execution in Outlook. The report highlights that these issues enable credential leakage and remote payload download (e.g., malicious sound files), notes active weaponization of a related Outlook bug by APT28, and recommends mitigations including blocking outbound SMB, disabling NTLM, or using the Protected Users security group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.