CVE-20223-23397 is an actively exploited zero-day vulnerability in Microsoft Outlook that allows attackers to obtain users’ Net-NTLMv2 hash and utilize the hash in an NTLM relay attack against another service, authenticated as the victim - otherwise known as spoofing.
The vulnerability scores a 9.8/10 CVSSv3.1 and can be exploited via email, potentially when the message is retrieved and processed by the server, meaning that exploitation could occur before the email is viewed by a user with the Preview Pane. Both 32 and 64-bit versions of Microsoft 365 Apps for Enterprise, Office 2013, 2016, and 2019 (as well as LTSC) are vulnerable to attack.
Administrators should patch within the day if possible since the vulnerability is relatively simple to exploit, doesn’t require user interaction, and is already being exploited in the wild. Microsoft has shared two temporary mitigations if you’re unable to patch immediately, both of which will impact NTLM and applications that use it so proceed with caution. The first option is adding users to the Protected User Security group which will prevent the use of NTLM as an authentication method, using this approach for high-value accounts like Domain administrators may be a reasonable approach. The other mitigation is to block TCP 445/SMB outbound on your firewall which will prevent sending NTLM authentication to remote fileshares.
CVE-2023-24880 is an actively exploited zero-day vulnerability affecting all Windows desktops (Windows 10 and above) and server editions (Server 2016, 2019, and 2022).
Microsoft Mark of the Web (MOTW) is a built-in Windows security feature that stops users from downloading or accessing malicious files from the internet by creating a zone identifier Alternate Data Stream (ADS), which enables Windows SmartScreen to block access to security features on the devices. However, the attacker can craft a malicious file bypassing the MOTW, resulting in a loss of device integrity and availability of security features in Microsoft office, such as Protected view, which relies on MOTW tags.
CVE-2023-23415 is a new network remote code execution vulnerability targeting Internet Control Message Protocols, or ICMP. Often used for error reporting, ICMP is a network layer protocol employed by network devices to diagnose communication issues by validating that data has reached its intended destination promptly.
An attacker can remotely exploit this vulnerability through the use of a low-level protocol error containing a fragmented IP packet in its header that is sent to the target machine. To trigger the vulnerable code path, an application on the target must be bound to a raw socket which allows for direct access to the IP. This vulnerability impacts a wide range of Microsoft products, including Windows 10, Windows 11 as well as Windows Server 2008, 2012, 2016, 2019, and 2022.
CVE-2023-23416 is a critical vulnerability that affects all versions of Windows desktops (Windows 10 and above) and server editions (Server 2012 and above). To exploit this vulnerability, the attacker must import a malicious certificate onto the host machine. This type of exploit is also known as Arbitrary Code Execution (ACE). The attacker or victim must execute code from the local machine to exploit this vulnerability.