Microsoft indirectly announced that all Windows versions of Outlook have a serious vulnerability. The company published its latest updates on Tuesday – like every Tuesday of the month. This time, one of the 80 so-called patches (in English: patches) was intended to close a hole in Outlook.
According to Microsoft’s “KrebsOnSecurity” cybercrime blog, the security update number CVE-2023-23397 is classified as “critical” with a severity rating of 9.8 (the maximum value is 10).
According to the company, the vulnerability has been actively exploited. “A Russian-based threat actor used the vulnerability patched in CVE-2023-23397 to launch attacks against a limited number of government, transportation, energy, and military organizations in Europe.”
According to Spiegel.de, the attackers are a hacker group called APT28, which is close to the Russian military intelligence service GRU. It is also known as Strontium, Sednit, Sofacy, and Fancy Bear.
The hackers used the vulnerability from April 2022 to December of the same year to gain access to the mail systems.
KrebsOnSecurity cybercrime experts write:
That means: On the other hand, it doesn’t even need to click a link or anything to open a port for the attackers. It is sufficient if the server accepts the message. This is similar “to an attacker who has a valid password and access to a company’s systems,” the blog quotes IT security expert Kevin Breen.
According to a Microsoft blog post, all Windows versions of Outlook that are still supported by Microsoft are affected by the vulnerability.
Outlook on the web running in the browser and the Outlook apps for Android iOS, macOS and all other services of the Microsoft 365 Office suite are immune because they don’t use the same technology.
(t-online/dsc)
Source: Watson
I’m Ella Sammie, author specializing in the Technology sector. I have been writing for 24 Instatnt News since 2020, and am passionate about staying up to date with the latest developments in this ever-changing industry.
On the same day of the terrorist attack on the Krokus City Hall in Moscow,…
class="sc-cffd1e67-0 iQNQmc">1/4Residents of Tenerife have had enough of noisy and dirty tourists.It's too loud, the…
class="sc-cffd1e67-0 iQNQmc">1/7Packing his things in Munich in the summer: Thomas Tuchel.After just over a year,…
At least seven people have been killed and 57 injured in severe earthquakes in the…
The American space agency NASA would establish a uniform lunar time on behalf of the…
class="sc-cffd1e67-0 iQNQmc">1/8Bode Obwegeser was surprised by the earthquake while he was sleeping. “It was a…