logo

Researchers Uncover How Outlook Vulnerability Could Leak Your NTLM Passwords

ID: 71ab342c-283d-5c7a-a7d2-c465c66e8a01

STIX ID: report--71ab342c-283d-5c7a-a7d2-c465c66e8a01

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2024-01-29

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A patched Outlook vulnerability (CVE-2023-35636, CVSS 6.5) allowed specially crafted files—delivered via email or hosted web content and leveraging calendar-sharing headers—to exfiltrate NTLM v2 hashed credentials; researcher Dolev Taler demonstrated leaks using Windows Performance Analyzer and File Explorer (those methods remain unpatched), enabling relay or offline brute-force attacks, and Microsoft addressed the issue in its December 2023 Patch Tuesday updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.