"Microsoft Outlook Vulnerabilities Spark Urgent Updates and Concerns"

TL;DR Summary
A critical vulnerability in Microsoft Outlook, rated 9.8 out of 10, has been exploited in the wild by a Russia-based threat actor. The exploit is triggered upon receipt of a malicious email and is executed before the email is read in the preview pane, requiring no user interaction. All currently supported versions of Outlook for Windows are impacted, but not Outlook for the web or those running on Android, iOS, or Mac. Microsoft has released a patch and published workaround mitigations, but multiple proofs-of-concept are now widely available, and the potential for harm is high.
- Microsoft Outlook Warning: Critical New Email Exploit Triggers Automatically—Update Now Forbes
- As CVE-2023-23397 exploits proliferate, worry mounts over CNI The Stack
- Microsoft Releases Updates to Patch Outlook NTLM Vulnerability Petri.com
- Microsoft Patch Tuesday, March 2023 Edition – Krebs on Security Krebs on Security
- Microsoft Pins Outlook Zero-Day Attacks on Russian Actor, Offers Detection Script SecurityWeek
Reading Insights
Total Reads
0
Unique Readers
17
Time Saved
5 min
vs 6 min read
Condensed
91%
1,006 → 95 words
Want the full story? Read the original article
Read on Forbes