TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Microsoft Outlook Elevation of Privilege Vulnerability (CVSS 9.8)

1 点作者 jenoer大约 2 年前

1 comment

jenoer大约 2 年前
This is a pretty big one (9.8).<p>&gt; The attacker could exploit this vulnerability by sending a specially crafted email which triggers automatically when it is retrieved and processed by the Outlook client. This could lead to exploitation BEFORE the email is viewed in the Preview Pane.<p>&gt; External attackers could send specially crafted emails that will cause a connection from the victim to an external UNC location of attackers&#x27; control. This will leak the Net-NTLMv2 hash of the victim to the attacker who can then relay this to another service and authenticate as the victim.<p>Microsoft has released a script to check for abuse: <a href="https:&#x2F;&#x2F;microsoft.github.io&#x2F;CSS-Exchange&#x2F;Security&#x2F;CVE-2023-23397&#x2F;" rel="nofollow">https:&#x2F;&#x2F;microsoft.github.io&#x2F;CSS-Exchange&#x2F;Security&#x2F;CVE-2023-2...</a>