CVE-2023-35636
published 2023-12-12CVE-2023-35636: Microsoft Outlook Information Disclosure Vulnerability
PriorityP340medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
17.56%
96.8th percentile
Microsoft Outlook Information Disclosure Vulnerability
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2016 | >= 16.0.0 < 16.0.5426.1000 | 16.0.5426.1000 |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7m3r-9jw9-j2rw: Microsoft Outlook Information Disclosure Vulnerability
ghsa_unreviewed·2023-12-12
CVE-2023-35636 [MEDIUM] GHSA-7m3r-9jw9-j2rw: Microsoft Outlook Information Disclosure Vulnerability
Microsoft Outlook Information Disclosure Vulnerability
Microsoft
Microsoft Outlook Information Disclosure Vulnerability
vendor_msrc·2023-12-12·CVSS 6.5
CVE-2023-35636 [MEDIUM] CWE-200 Microsoft Outlook Information Disclosure Vulnerability
Microsoft Outlook Information Disclosure Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
Exploitation of the vulnerability requires that a user open a specially crafted file.
In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file.
In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability.
An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of a
Suricata
ET EXPLOIT Possible Malicious x-sharing-config-url SMTP header observed (CVE-2023-35636)
suricata·2024-01-24·CVSS 6.5
CVE-2023-35636 [MEDIUM] ET EXPLOIT Possible Malicious x-sharing-config-url SMTP header observed (CVE-2023-35636)
ET EXPLOIT Possible Malicious x-sharing-config-url SMTP header observed (CVE-2023-35636)
Rule: alert smtp any any -> $HOME_NET any (msg:"ET EXPLOIT Possible Malicious x-sharing-config-url SMTP header observed (CVE-2023-35636)"; flow:established,to_server; content:"Content-Class|3a 20|Sharing"; nocase; content:"x-sharing-config-url|3a 20|\\"; fast_pattern; nocase; content:".ics"; within:50; reference:url,www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes; reference:cve,2023-35636; classtype:credential-theft; sid:2050433; rev:1; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Windows_11, attack_target Client_Endpoint, created_at 2024_01_24, cve CVE_2023_35636, deployment Perimeter, deployment SSLDecrypt, performance_impact Low, confi
Suricata
ET HUNTING External SMB ANDX Request for Outlook Calendar Invite File (.ics) - Possible NTLM Hash Leak Attempt
suricata·2024-01-24
CVE-2023-35636 ET HUNTING External SMB ANDX Request for Outlook Calendar Invite File (.ics) - Possible NTLM Hash Leak Attempt
ET HUNTING External SMB ANDX Request for Outlook Calendar Invite File (.ics) - Possible NTLM Hash Leak Attempt
Rule: alert smb $HOME_NET any -> $EXTERNAL_NET any (msg:"ET HUNTING External SMB ANDX Request for Outlook Calendar Invite File (.ics) - Possible NTLM Hash Leak Attempt"; flow:established,to_server; content:"|ff|SMB"; depth:8; content:"|00 2E 00|i|00|c|00|s|00 00 00|"; nocase; fast_pattern; endswith; reference:url,www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes; reference:cve,2023-35636; classtype:credential-theft; sid:2050432; rev:1; metadata:affected_product Windows_11, attack_target Client_Endpoint, created_at 2024_01_24, cve CVE_2023_35636, deployment SSLDecrypt, performance_impact Low, confidence Low, signature_severity Major, updated_at 2024_01_24; ta
No public exploits indexed.
Hackernews
Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
blogs_hackernews·2026-06-03·CVSS 4.3
CVE-2026-33829 [MEDIUM] Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker.
Like in the case of CVE-2026-33829 , which impacted the Windows Snipping Tool's ms-screensketch: URI handler, the newly flagged issue resides in the search: URI handler, per Huntress .
CVE-2026-33829 refers to a spoofing vulnerability that could expose sensitive information to an unauthorized actor. It was patched by Microsoft in April 2026.
"An attacker could induce the user into clicking a specially cr
Bleepingcomputer
Microsoft pulls fix for Outlook bug behind ICS security alerts
blogs_bleepingcomputer·2024-04-23·CVSS 6.5
[MEDIUM] Microsoft pulls fix for Outlook bug behind ICS security alerts
## Microsoft pulls fix for Outlook bug behind ICS security alerts
## Sergiu Gatlan
Microsoft has rolled back a fix for a known Outlook issue that was causing incorrect security alerts when opening ICS calendar files after installing the December Outlook Desktop security updates.
Affected Microsoft 365 users are seeing unexpected warnings that "Microsoft Office has identified a potential security concern" and that "This location may be unsafe" when double-clicking ICS files saved on their devices.
The December security updates triggering these alerts patch an Outlook information disclosure vulnerability ( CVE-2023-35636 ) that can let attackers steal NTLM hashes via maliciously crafted files and use them in Windows pass-the-hash attacks to access sensitive data or move laterally on the
Bleepingcomputer
Microsoft Outlook December updates trigger ICS security alerts
blogs_bleepingcomputer·2024-02-05·CVSS 6.5
CVE-2023-35636 [MEDIUM] Microsoft Outlook December updates trigger ICS security alerts
## Microsoft Outlook December updates trigger ICS security alerts
## Sergiu Gatlan
The company also revealed that the security warning will be displayed after deploying a security update that patches the CVE-2023-35636 Microsoft Outlook information disclosure vulnerability.
If left unpatched, the security flaw can be exploited by attackers to trick users of unpatched Outlook installations into opening maliciously crafted files to steal NTLM hashes (their obfuscated Windows credentials).
The attackers can later use them to authenticate as the compromised user, gain access to sensitive data, or spread laterally on their network.
## Workaround available
Until a resolution is available, Redmond shared a temporary fix for those impacted in the form of a registry key that would disable th
Krebs
Microsoft Patch Tuesday, December 2023 Edition
blogs_krebs·2023-12-13·CVSS 8.1
[HIGH] Microsoft Patch Tuesday, December 2023 Edition
The final Patch Tuesday of 2023 is upon us, with Microsoft Corp. today releasing fixes for a relatively small number of security holes in its Windows operating systems and other software. Even more unusual, there are no known “zero-day” threats targeting any of the vulnerabilities in December’s patch batch. Still, four of the updates pushed out today address “critical” vulnerabilities that Microsoft says can be exploited by malware or malcontents to seize complete control over a vulnerable Windows device with little or no help from users.
Among the critical bugs quashed this month is CVE-2023-35628, a weakness present in Windows 10 and later versions, as well as Microsoft Server 2008 and later. Kevin Breen, senior director of threat research at Immersive Labs, said the flaw affects MSHTML
Trendmicro
The December 2023 Security Update Review
blogs_trendmicro·2023-12-12
The December 2023 Security Update Review
# The December 2023 Security Update Review
Get the December 2023 security update and review.
By: Zero Day Initiative
2023/12/12
Read time: ( words)
Save to Folio
It’s the final patch Tuesday of 2023, and Apple, Adobe, and Microsoft have released their latest security offerings. Take a break from your holiday hustle and join us as we review the details of their latest advisories. If you’d rather watch the video recap, you can check it out here:
Apple Patches for December 2023
Apple kicked off the December release cycle with patches for iOS and iPadOS with eight CVEs. Two of these CVEs in Webkit are reported as being under active attack on iOS versions 16.7.1 and older. If you’re using an older iPhone or iPad, you should definitely update your device immediately. If you’re using a dev
Krebs
Microsoft Patch Tuesday, December 2023 Edition
blogs_krebs·2023-12-12·CVSS 8.1
[HIGH] Microsoft Patch Tuesday, December 2023 Edition
The final Patch Tuesday of 2023 is upon us, with Microsoft Corp. today releasing fixes for a relatively small number of security holes in its Windows operating systems and other software. Even more unusual, there are no known “zero-day” threats targeting any of the vulnerabilities in December’s patch batch. Still, four of the updates pushed out today address “critical” vulnerabilities that Microsoft says can be exploited by malware or malcontents to seize complete control over a vulnerable Windows device with little or no help from users.
Among the critical bugs quashed this month is CVE-2023-35628 , a weakness present in Windows 10 and later versions, as well as Microsoft Server 2008 and later. Kevin Breen , senior director of threat research at Immersive Labs , said the flaw affects MSH
Talos
Microsoft releases lightest Patch Tuesday in three years, no zero-days disclosed
blogs_talos·2023-12-12·CVSS 8.1
[HIGH] Microsoft releases lightest Patch Tuesday in three years, no zero-days disclosed
Microsoft’s monthly security update released Tuesday is the company’s lightest in four years, including only 33 vulnerabilities.
Perhaps more notable is that there are no zero-day vulnerabilities included in December’s Patch Tuesday, a rarity for Microsoft this year. The company’s regular set of advisories has included a vulnerability that’s been actively exploited in the wild in 10 months this year.
However, there are four critical vulnerabilities that Microsoft released patches, three of which could lead to remote code execution. The remainder of this month’s vulnerabilities are considered “important.” Thirty-three vulnerabilities are the lowest number included in a Patch Tuesday since December 2019.
Two of the critical vulnerabilities are CVE-2023-35630 and CVE-2023-35641, which exis
Bleepingcomputer
Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
blogs_bleepingcomputer·2023-12-12·CVSS 5.5
[MEDIUM] Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
## Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day
## Lawrence Abrams
10 Elevation of Privilege Vulnerabilities
8 Remote Code Execution Vulnerabilities
6 Information Disclosure Vulnerabilities
5 Denial of Service Vulnerabilities
5 Spoofing Vulnerabilities
The total count of 34 flaws does not include 8 Microsoft Edge flaws fixed on December 7th.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5033375 cumulative update and Windows 10 KB5033372 cumulative update .
## One publicly disclosed zero-day fixed
This month's Patch Tuesday fixes one AMD zero-day vulnerability disclosed in August that previously remained unpatched.
The ' CVE-2023-20588 - AMD: CVE-2023-20588 AMD Speculative Leaks ' vul
Talos
Microsoft releases lightest Patch Tuesday in three years, no zero-days disclosed
blogs_talos·2023-12-12·CVSS 8.1
[HIGH] Microsoft releases lightest Patch Tuesday in three years, no zero-days disclosed
## Microsoft releases lightest Patch Tuesday in three years, no zero-days disclosed
Microsoft’s monthly security update released Tuesday is the company’s lightest in four years, including only 33 vulnerabilities.
Perhaps more notable is that there are no zero-day vulnerabilities included in December’s Patch Tuesday, a rarity for Microsoft this year. The company’s regular set of advisories has included a vulnerability that’s been actively exploited in the wild in 10 months this year.
However, there are four critical vulnerabilities that Microsoft released patches, three of which could lead to remote code execution. The remainder of this month’s vulnerabilities are considered “important.” Thirty-three vulnerabilities are the lowest number included in a Patch Tuesday since December 2019.
2023-12-12
Published