Rewterz
Rewterz Threat Update – Microsoft Warns of OAuth Apps Utilized for Automatic BEC and Cryptomining Attacks
December 13, 2023
Rewterz
Rewterz Threat Alert – Remcos RAT – Active IOCs
December 13, 2023

Rewterz Threat Advisory – Multiple Microsoft Outlook Vulnerabilities

Severity

High

Analysis Summary

CVE-2023-35619 CVSS:5.3

Microsoft Outlook for Mac could allow a remote attacker to conduct spoofing attacks. An attacker could exploit this vulnerability to inject CSS into an email.

CVE-2023-35636 CVSS: 6.5

Microsoft Outlook could allow a remote attacker to obtain sensitive information. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to obtain NTLM hashes and use this information to launch further attacks against the affected system.

Impact

  • Gain Access
  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2023-35619
  • CVE-2023-35636

Affected Vendors

Microsoft

Affected Products

  • Microsoft 365 Apps for Enterprise x32
  • Microsoft 365 Apps for Enterprise x64
  • Microsoft Office 2016 x32
  • Microsoft Office 2016 x64
  • Microsoft Office LTSC 2021 x32
  • Microsoft Office LTSC 2021 x64
  • Microsoft Office 2019 x32
  • Microsoft Office 2019 x64
  • Microsoft Office LTSC for Mac 2021

Remediation

Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

CVE-2023-35619

CVE-2023-35636