Microsoft addresses multiple zero-day vulnerabilities in latest patch update.

1 min read
Source: BleepingComputer
Microsoft addresses multiple zero-day vulnerabilities in latest patch update.
Photo: BleepingComputer
TL;DR Summary

Microsoft has fixed a security vulnerability that could be used by remote attackers to bypass recent patches for a critical Outlook zero-day security flaw abused in the wild. The vulnerability impacts all supported versions of Windows and was reported by Akamai security researcher Ben Barnea. The Outlook zero-day bug patched in March is a privilege escalation flaw in the Outlook client for Windows that enables attackers to steal NTLM hashes without user interaction in NTLM-relay attacks. The vulnerability was exploited by Russian APT28 state hackers in attacks against at least 14 government, military, energy, and transportation organizations between mid-April and December 2022.

Share this article

Reading Insights

Total Reads

0

Unique Readers

9

Time Saved

2 min

vs 3 min read

Condensed

78%

461102 words

Want the full story? Read the original article

Read on BleepingComputer