filmov
tv
Russian Malicious Outlook Calendar Invites Targeting Ukraine (CVE-2023-23397) | Threat SnapShot
![preview_player](https://i.ytimg.com/vi/YUahaknpKUY/maxresdefault.jpg)
Показать описание
In this week's Threat SnapShot, we'll take a look at a privilege escalation attack affecting Microsoft Outlook that has been used by a Russian nation-state actor (APT28, Fancy Bear, GRU) against organizations in Ukraine. The vulnerability, CVE-2023-23397, was addressed in Microsoft's most recent patch Tuesday (March 2023). Evidence of exploitation, however, has been seen to date back to at least April 2022. The attack leverages a relatively obscure feature of Outlook, where calendar invites can contain a file path for an alternative notification sound. An attacker can specify a UNC path, and Outlook will happily pass along the user's NTLM credentials to try to authenticate to that path, leading to an escalation of privilege and credential compromise.
We'll take a closer look at three example attack variations using this vulnerability -- one that passes the credentials via WebDAV, another that relays the NTLM credentials to gain an SMB shell on the victim, and a third that uses this vulnerability as a persistence mechanism by setting a registry key. We'll also discuss detection and threat hunting strategies to protect your organization from each of these attack vectors.
Resources:
SnapAttack Content:
We'll take a closer look at three example attack variations using this vulnerability -- one that passes the credentials via WebDAV, another that relays the NTLM credentials to gain an SMB shell on the victim, and a third that uses this vulnerability as a persistence mechanism by setting a registry key. We'll also discuss detection and threat hunting strategies to protect your organization from each of these attack vectors.
Resources:
SnapAttack Content:
Russian Malicious Outlook Calendar Invites Targeting Ukraine (CVE-2023-23397) | Threat SnapShot
Russian Hackers Using Outlook Flaw for a Year
Hunting Russia FSB's Most Sophisticated 'Snake' Malware | Threat SnapShot
THM Outlook NTLM Leak CVE 2023023397 Walkthrough
NEVER buy from the Dark Web.. #shorts
Digging into CVE-2023-23397
Security fix released by MS for Outlook vulnerabilities on March's Patch Tuesday
Microsoft Outlook NTLM Leak | Walkthrough | TryHackMe | CVE-2023-23397 Security Vulnerability
How Microsoft fixed a radical Outlook security flaw that could expose your emails
Critical Outlook Vulnerability!? Patch Tuesday News! Windows 11 Slowness Addressed!
Outlook NTLM Leak Tryhackme - CVE-2023-23397
Top 5 Vulnerabilities of 2022 feat. Tenable Threat Landscape Report
Microsoft Outlook vulnerability CVE 2023-23397 - Threat Talks Cybersecurity Podcast
2023 'All In' Breakout Sessions - Mike Ritsema - Microsoft Tips and Tricks
AICPA Town Hall Series - March 17 Edition
Microsoft Outlook NTLM Vulnerability | CVE-2023-23397 Demo
DarkRelay's POC and demo on CVE-2023-23397: Critical Microsoft Outlook vulnerability
WEBINAR: Why Your Business Needs Cyber Security
REvil Ransomware Kaseya Supply-Chain Attack: Analysis and Countermeasures
How to Protect Your Company from Cyber Attacks
Microsoft 365 - Why You Need It Now More Than Ever
Watch the Full Virtual Cybersecurity Tech Event | Proven IT
Webinar: Best of 2023
TALK19 - Julien Nocetti – Cyber-related threats & Geopolitics: Upgrading the level-playing exper...
Комментарии