CERT-In Vulnerability Note
CIVN-2023-0077
Privilege Escalation Vulnerability in Microsoft Outlook
Original Issue Date:March 15, 2023
Severity Rating: CRITICAL
Software Affected
- Microsoft Outlook 2016 for 32-bit editions and 64-bit editions
- Microsoft Outlook 2013 Service Pack 1 for 32-bit editions and 64-bit editions
- Microsoft Outlook 2013 RT Service Pack 1
- Microsoft Office 2019 for 32-bit editions and 64-bit editions
- Microsoft 365 Apps for Enterprise for 32-bit Systems and 64-bit Systems
- Microsoft Office LTSC 2021 for 32-bit editions and 64-bit editions
Overview
A vulnerability has been reported in Microsoft Outlook, which could allow a remote attacker to gain elevated privileges on the targeted system.
Description
This vulnerability exists in Microsoft Outlook due to the application leaks the Net-NTLMv2 hash of a user¿s account which could be used as a basis of an NTLM Relay attack against another service to authenticate as the user. An attacker could exploit this vulnerability by sending specially crafted email which triggers automatically when it is retrieved and processed by the email server. This could lead to exploitation before the email is viewed in the preview pane. Successful exploitation of this vulnerability could allow a remote attacker to gain elevated privileges and completely compromise the affected system.
Note: This vulnerability (CVE-2023-23397) is being exploited in the wild. Users are advised to apply patches urgently.
Solution
Apply appropriate security updates as mentioned in the below link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397
References
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397
CVE Name
CVE-2023-23397
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|