Skip to main content

Search

Items tagged with: cve202323397


You definitely want to update Microsoft Office.

MDSec beat me to it on CVE-2023-23397, it's supppper easy to exploit + works with remote images disabled - turns out the spec (which is open) has a function to specify a sound when an Outlook email arrives - which loads via UNC and sends NTML password hash for AD account to internet = no click cred theft, PoC in wild.

#CVE202323397 mdsec.co.uk/2023/03/exploiting…

Lo, thar be cookies on this site to keep track of your login. By clicking 'okay', you are CONSENTING to this.

⇧