Microsoft Outlook Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H), integrity (I:H) and availability (A:H). What does that mean for this vulnerability? An attacker who successfully exploited this vulnerability could access a user's Net-NTLMv2 hash which could be used as a basis of an NTLM Relay attack against another service to authenticate as the user.
Is the Preview Pane an attack vector for this vulnerability? The attacker could exploit this vulnerability by sending a specially crafted email which triggers automatically when it is retrieved and processed by the Outlook client. This could lead to exploitation BEFORE the email is viewed in the Preview Pane.
How could an attacker exploit this vulnerability? External attackers could send specially crafted emails that will cause a connection from the victim to an untrusted location of attackers' control. This will leak the Net-NTLMv2 hash of the victim to the untrusted network which an attacker can then relay to another service and authenticate as the victim.
Where can I find more information about NTLM relay attacks? Download Mitigating Pass the Hash (PtH) Attacks and Other Credential Theft, Version 1 and 2. This document discusses Pass-the-Hash (PtH) attacks against the Windows operating systems and provides holistic planning strategies that, when combined with the Windows security features, will provide a more effective defense against pass-the-hash attacks.
Where can I find more information? Please see the MSRC Blog Post relating to this vulnerability here: Microsoft Mitigates Outlook Elevation of Privilege Vulnerability.
🎯 Affected products11
- Microsoft 365 Apps for Enterprise for 32-bit Systems
- Microsoft 365 Apps for Enterprise for 64-bit Systems
- Microsoft Office 2019 for 32-bit editions
- Microsoft Office 2019 for 64-bit editions
- Microsoft Office LTSC 2021 for 32-bit editions
- Microsoft Office LTSC 2021 for 64-bit editions
- Microsoft Outlook 2013 RT Service Pack 1
- Microsoft Outlook 2013 Service Pack 1 (32-bit editions)
- Microsoft Outlook 2013 Service Pack 1 (64-bit editions)
- Microsoft Outlook 2016 (32-bit edition)
- Microsoft Outlook 2016 (64-bit edition)
✅ Remediation
KBClick to Run (Security Update) — fixed build https://aka.ms/OfficeSecurityReleases KB5002254 (Security Update) — fixed build 16.0.5387.1000 KB5002265 (Security Update) — fixed build 15.0.5537.1000
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397
- patchhttps://www.microsoft.com/download/details.aspx?familyid=65194ac0-3b9d-4345-84b2-c66bd196a91d
- patchhttps://www.microsoft.com/download/details.aspx?familyid=e78aa39d-7d9b-4d01-98e0-f058ff3b2db3
- patchhttps://www.microsoft.com/download/details.aspx?familyid=daf1d545-d8c8-471f-b392-d60d25e14828
- patchhttps://www.microsoft.com/download/details.aspx?familyid=328f72f0-7eea-4e9b-acae-82851622dbe0