Microsoft addresses multiple zero-day vulnerabilities in latest patch update.

Microsoft has fixed a security vulnerability that could be used by remote attackers to bypass recent patches for a critical Outlook zero-day security flaw abused in the wild. The vulnerability impacts all supported versions of Windows and was reported by Akamai security researcher Ben Barnea. The Outlook zero-day bug patched in March is a privilege escalation flaw in the Outlook client for Windows that enables attackers to steal NTLM hashes without user interaction in NTLM-relay attacks. The vulnerability was exploited by Russian APT28 state hackers in attacks against at least 14 government, military, energy, and transportation organizations between mid-April and December 2022.
- Microsoft patches bypass for recently fixed Outlook zero-click bug BleepingComputer
- Microsoft will take nearly a year to finish patching new 0-day Secure Boot bug Ars Technica
- Microsoft releases fix for patched Outlook issue exploited by Russian hackers The Record by Recorded Future
- Microsoft fixes 38 flaws, including 3 zero-day vulnerabilities, with Patch Tuesday update TechSpot
- Experts Detail New Zero-Click Windows Vulnerability for NTLM Credential Theft The Hacker News
Reading Insights
0
9
2 min
vs 3 min read
78%
461 → 102 words
Want the full story? Read the original article
Read on BleepingComputer