TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Microsoft Outlook Elevation of Privilege Vulnerability (CVSS 9.8)

1 pointsby jenoerabout 2 years ago

1 comment

jenoerabout 2 years ago
This is a pretty big one (9.8).<p>&gt; The attacker could exploit this vulnerability by sending a specially crafted email which triggers automatically when it is retrieved and processed by the Outlook client. This could lead to exploitation BEFORE the email is viewed in the Preview Pane.<p>&gt; External attackers could send specially crafted emails that will cause a connection from the victim to an external UNC location of attackers&#x27; control. This will leak the Net-NTLMv2 hash of the victim to the attacker who can then relay this to another service and authenticate as the victim.<p>Microsoft has released a script to check for abuse: <a href="https:&#x2F;&#x2F;microsoft.github.io&#x2F;CSS-Exchange&#x2F;Security&#x2F;CVE-2023-23397&#x2F;" rel="nofollow">https:&#x2F;&#x2F;microsoft.github.io&#x2F;CSS-Exchange&#x2F;Security&#x2F;CVE-2023-2...</a>