Another MS Outlook vulnerability

In the end of the 2023 a new Microsoft Outlook vulnerability has been identified and labeled CVE-2023-35636. Exploiting this vulnerability allows the adversary to obtain the user’s password hash. This hash can later be used for discovering a cleartext password.

In order to exploit this CVE the user’s PC must be infected with the specific malware, therefore two basic attack scenarios can be outlined:

    1. Email-based attack. The adversary must send the malware via email attachment and persuade the user to open it.
    2. Web-based attack. The malware is deployed on a website, masked as a legitimate downloadable content.

Currently, Microsoft has released an update for the MS Office suite, that fixes the described security flaw, so if you are using MS Outlook, make sure that you have all latest updates installed.

Unfortunately, the risks associated with vulnerabilities in web browsers and email clients are here to stay and opening suspicious links or files received from dubious or unknown senders may result in a cybersecurity incident. The strategy for minimizing these risks should be based on a combination of technical cybersecurity solutions, focused on safe browsing and email filtering, with users’ awareness and training.

Contact UDV Technologies for more info on how to protect your Company’s communication services with comprehensive security products from the leading vendors. We also encourage you to consider trying the Security Awareness Training to boost your employees’ awareness of the current threat landscape and empower them with skills and knowledge essential for maintaining the digital hygiene.

Looking forward to hearing from you and stay safe and secure.

Contact us

Thank you. Your message is now being processed.

Fill in the field

Fill in the field

Fill in the field

Fill in the field

Fill in the field

Fill in the field

Fill in the field