Need urgent help?

Call our team on 0207 099 0740

Need urgent help?
0207 099 0740
Client Portal
view of earth from space which shows some areas with lights on as it is night time

20 March 2023

2 minutes read time

Outlook Vulnerability (CVE-2023-23397) – What To Know

Author

As Chief Information Security Officer at CloudTech24, I lead security strategy, governance and operational delivery. I help our clients’ executive teams make informed decisions about cyber risk. My role involves understanding how a customer’s business actually works, where the real risks sit, and what it takes to reduce them in a way that lasts, using existing capabilities wherever possible.

My background spans hands-on technical delivery and board-level advisory to clients across fintech, financial services, legal and other regulated industries. I also own our ISO 27001 programme and the ISMS behind it. As AI moves into everyday business use, I also ensure that our usage of AI aligns to best practise through governance and policy, and advise leadership and customers on safe adoption, aligning toward emerging standards such as ISO 42001 and the EU AI Act.

Outside of work, I’m a proud dad to two brilliant daughters and a lifelong LEGO enthusiast – if we’ve had a video call, chances are you’ve seen a few of my builds in the background. I’m also a passionate gamer and PC builder, a hobby I picked up in the early 2000s with my dad, who first sparked my interest in computers. Fun fact: back in the day, I was Europe’s #1 ranked Battlefield 1942 player – proof that my competitive streak goes way back!

Read blogs in other categories

Cloudtech-Logo-onWhite

On March 14th, 2023, Microsoft released details of a critical (9.8/10) vulnerability relating to Outlook clients globally which was discovered and submitted by the Computer Emergency Response Team (CERT) of Ukraine (UA).

What makes this vulnerability particularly severe is the fact that unlike traditional phishing, which requires a user to open a malicious attachment or link, this exploit requires no user interaction to operate based on proof of concepts already developed by the research community.

How does CVE-2023-23397 work?

In summary, attackers can weaponise a calendar invite or appointment with additional properties and when emailed to a victim, it causes the “Reminder Notification” and associated sound to trigger, which is typically used to remind the user that the proposed meeting is either overdue, or is about to start.

It was discovered that it is possible to customise this notification sound and instead of configuring a sound to play, attackers can put the path to a remote resource such as a malicious external host, using a Universal naming convention (UNC) path. This meant that when the reminder notification triggers, it also causes unwanted connections to this malicious host using the Server Message Block (SMB) protocol (normally used for network file sharing) and perform NTLM authentication, exposing the hashes which can then be used by attackers to perform pass-the-hash attacks.

What Can I Do?

The good news is that Microsoft have already released a set of patches along with details of this vulnerability. The best course of action at this time to ensure Microsoft patches are prioritised as quickly as possible to mitigate possible use of the vulnerability. Links to the Microsoft vulnerability and associated patches are below.

For defenders, monitoring or blocking outbound connections to 445/SMB is another step if patching is not immediately viable. It is advisable, however, that this is taken into consideration on a case-by-case basis as 445/SMB is a legitimate protocol and may be used by organisational services.

References:

Microsoft Vulnerability page

Back to blog

Recent blogs from CT24

What is a virtual CISO (vCISO)?

Cybersecurity issues don’t pop up one at a time. They’re often frequent, urgent, and complex. When issues build up and the level of complexity increases to the point where your team needs an extra hand, having a vCISO can lighten the load. A vCISO (Virtual Chief Information Security Officer) is a security leader who serves…

Read more

Which one is better – AWS, Azure, or Google Cloud?

Choosing the right cloud infrastructure is a decision you can’t take lightly. Today, businesses must decide whether to build their applications on AWS, Azure, or Google Cloud. While these platforms offer similar core features like storage and computing power, each vendor approaches infrastructure, security, and developer experience with a completely different philosophy. This blog breaks…

Read more

The role of ethical hacking in penetration testing

Hacking into a business is, 99% of the time, a malicious act aimed at damaging an organisation. But penetration testing is that 1%, where it’s actually an incredibly safe and skilful way to find how you can improve your business.  In this guide, we’ll cover what penetration testing is, how it works, the process, and…

Read more