Categories: Technology

After attacks from Russia: Microsoft warns of serious security vulnerabilities in Outlook

For a year now, attackers from Russia have been attacking companies through a vulnerability in all Windows versions of Outlook. What sounds like a spy thriller might worry you too.

Microsoft indirectly announced that all Windows versions of Outlook have a serious vulnerability. The company published its latest updates on Tuesday – like every Tuesday of the month. This time, one of the 80 so-called patches (in English: patches) was intended to close a hole in Outlook.

According to Microsoft’s “KrebsOnSecurity” cybercrime blog, the security update number CVE-2023-23397 is classified as “critical” with a severity rating of 9.8 (the maximum value is 10).

Fancy Bear exploited a vulnerability

According to the company, the vulnerability has been actively exploited. “A Russian-based threat actor used the vulnerability patched in CVE-2023-23397 to launch attacks against a limited number of government, transportation, energy, and military organizations in Europe.”

According to Spiegel.de, the attackers are a hacker group called APT28, which is close to the Russian military intelligence service GRU. It is also known as Strontium, Sednit, Sofacy, and Fancy Bear.

The hackers used the vulnerability from April 2022 to December of the same year to gain access to the mail systems.

How is it attacked?

KrebsOnSecurity cybercrime experts write:

“The known vulnerability allows an attacker to obtain someone else’s NTLM hash (the Windows account password, editor’s note) and use it in an attack.”

That means: On the other hand, it doesn’t even need to click a link or anything to open a port for the attackers. It is sufficient if the server accepts the message. This is similar “to an attacker who has a valid password and access to a company’s systems,” the blog quotes IT security expert Kevin Breen.

Who is affected?

According to a Microsoft blog post, all Windows versions of Outlook that are still supported by Microsoft are affected by the vulnerability.

Outlook on the web running in the browser and the Outlook apps for Android iOS, macOS and all other services of the Microsoft 365 Office suite are immune because they don’t use the same technology.

Sources

  • krebsonsecurity.com: “Microsoft Tuesday March 2023 Patch Edition”
  • mcrc.microsoft.com: “Security Update Guide”
  • msrc.microsoft.com: “Microsoft Mitigates Elevation of Privilege Vulnerability in Outlook”
  • mirror.de: Microsoft Warns of Critical Outlook Vulnerability

(t-online/dsc)

Source: Watson

Share
Published by
Ella

Recent Posts

Terror suspect Chechen ‘hanged himself’ in Russian custody Egyptian President al-Sisi has been sworn in for a third term

On the same day of the terrorist attack on the Krokus City Hall in Moscow,…

1 year ago

Locals demand tourist tax for Tenerife: “Like a cancer consuming the island”

class="sc-cffd1e67-0 iQNQmc">1/4Residents of Tenerife have had enough of noisy and dirty tourists.It's too loud, the…

1 year ago

Agreement reached: this is how much Tuchel will receive for his departure from Bayern

class="sc-cffd1e67-0 iQNQmc">1/7Packing his things in Munich in the summer: Thomas Tuchel.After just over a year,…

1 year ago

Worst earthquake in 25 years in Taiwan +++ Number of deaths increased Is Russia running out of tanks? Now ‘Chinese coffins’ are used

At least seven people have been killed and 57 injured in severe earthquakes in the…

1 year ago

Now the moon should also have its own time (and its own clocks). These 11 photos and videos show just how intense the Taiwan earthquake was

The American space agency NASA would establish a uniform lunar time on behalf of the…

1 year ago

This is how the Swiss experienced the earthquake in Taiwan: “I saw a crack in the wall”

class="sc-cffd1e67-0 iQNQmc">1/8Bode Obwegeser was surprised by the earthquake while he was sleeping. “It was a…

1 year ago