No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Microsoft Fixes Failed Patch for Exploited Outlook Vulnerability

May 14, 2023
in Protection
0
Microsoft Fixes Failed Patch for Exploited Outlook Vulnerability



Call it a patch for a broken patch.

Microsoft’s May 2023 security update includes a patch for a vulnerability that allows attackers to easily bypass a fix the company issued in March for a critical privilege-escalation bug in Outlook that attackers have already exploited.

That bug, tracked as CVE-2023-23397, allows attackers a way to steal a user’s password hash by coercing the victim’s Microsoft Outlook client to connect to an attacker-controlled server. Microsoft, at the time, addressed the issue with a patch that essentially prevented the Outlook client from making such connections.

But a researcher from Akamai examining the fix found another issue in a related Internet Explorer component that allowed him to bypass the patch altogether — by adding just a single character to it.

Microsoft assigned a separate identifier for the new bug (CVE-2023-29324) and issued a patch for it in this month’s Patch Tuesday batch.

In its vulnerability release notes, Microsoft described the CVE-2023-29324 as a bug that allows attackers to craft a malicious URL that could evade the zone checks the company had implemented in the patch for the March flaw.

This could result in “a limited loss of integrity and availability of the victim machine,” Microsoft said. The company assessed the bug to be of moderate severity even though it also described it as one that attackers are more likely to exploit.

Microsoft is advising organizations to implement both the March patch for CVE-2023-23397 and the May patch for CVE-2023-29324 to be fully protected.

Dangerous Outlook Vulnerability

CVE-2023-29324 is a remotely exploitable, zero-click vulnerability that renders the patch for the original Outlook vulnerability useless, researchers at Akamai say.

“The vulnerability is easily triggered, as [it] doesn’t require any special expertise,” says Ben Barnea, the researcher at Akamai who discovered the new bug. “In fact, there are many PoCs available on the Internet for the original Outlook vulnerability, and they can be easily adapted to use the new bypass.”

The original Outlook flaw, CVE-2023-23397, is a bug that basically allows an unauthenticated attacker to steal a user’s NTLM credentials — or password hash — and use them to authenticate to other services. Attackers can exploit the flaw by sending the victim a specially crafted email that triggers automatically when the Outlook client retrieves and processes the email — and before the user has even viewed it in the Preview Pane.

Attackers can use the vulnerability to force a connection from the victim’s Outlook client to an attacker-controlled server so they could steal the victims NTLM hash. The bug affects all supported Windows versions.

Abusing Outlook’s Custom Notification Sound

Barnea’s analysis of the bug showed it stemmed from the manner in which Outlook handles emails containing a reminder with a custom notification sound.

The bug allows an attacker to specify what is known as a UNC path that would cause the Outlook client to retrieve the sound file from any SMB server including an attacker controller one. A Universal Naming Convention (UNC) naming path basically provides a standard way to locate and access shared resources on a network such as files, folders, and printers.

Microsoft addressed the issue by ensuring the relevant Outlook code calls a Windows API function (called MapUrlToZone) that verifies the security zone of a given URL. Security zones in Windows can include local machine zone, intranet zone, and trusted zones. The patch ensures that if the path to the sound file pointed to an Internet URL, the default reminder sound from a local security zone is used instead of the custom audio sound, Akamai said.

Barnea found that by adding a single ‘\’ to the UNC path, an attacker could create a URL that MapUrlToZone would assess as belonging in the local security zone, while also allowing the custom audio file to be downloaded from an external SMB server.

“MapUrlToZone is problematic here. It’s used as a security measure, but the function itself contained a bug,” Barnea says.

The patch for the original Outlook vulnerability (CVE-2023-23397) used a function that’s supposed to parse a path and return whether it’s local or remote.

“This addition was meant to prevent an outgoing connection from Outlook to remote servers to fetch a notification sound file,” Barnea says. “We found a specific path for which the function incorrectly returns a wrong verdict — ‘local’ instead of ‘remote.’ This allows us to ‘fool’ the function and use this path to exploit the original Outlook vulnerability.”

“Remove” It

Barnea says the original Outlook vulnerability and the subsequent bypass flaw that Akamai discovered are the only two instances the company knows of that targeted the custom reminder sound feature in Outlook. However, for attackers the feature presents an interesting surface for remote, unauthenticated attacks, he says. “We believe it should be removed altogether.”

Microsoft did not respond immediately to a Dark Reading request for comment on Akamai’s claims about the severity of the bug and the threat it presents.

Editorial Team

Editorial Team

Related Posts

What Happens Now That Meta and YouTube Were Found Legally Negligent
Protection

What Happens Now That Meta and YouTube Were Found Legally Negligent

March 26, 2026
If I Had a Home Gym, This Is the Storage Rack I'd Buy During Amazon's Spring Sale
Protection

If I Had a Home Gym, This Is the Storage Rack I’d Buy During Amazon’s Spring Sale

March 26, 2026
This Budget Fitbit Is Only $70 During Amazon's Big Spring Sale
Protection

This Budget Fitbit Is Only $70 During Amazon’s Big Spring Sale

March 26, 2026
This Surprisingly Powerful Compressed Air Duster Is 27% Off Today
Protection

This Surprisingly Powerful Compressed Air Duster Is 27% Off Today

March 26, 2026
Google's Pixel Buds Pro 2 Are $60 Off for the Amazon Big Spring Sale
Protection

Google’s Pixel Buds Pro 2 Are $60 Off for the Amazon Big Spring Sale

March 25, 2026
Roblox Gift Cards Are Majorly Discounted During Amazon's Big Spring Sale
Protection

Roblox Gift Cards Are Majorly Discounted During Amazon’s Big Spring Sale

March 25, 2026
Load More
Next Post
What Is a Good 401(k) Match? How It Works and What's the Average

What Is a Good 401(k) Match? How It Works and What's the Average

Popular News

  • Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    0 shares
    Share 0 Tweet 0
  • BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

    0 shares
    Share 0 Tweet 0
  • L&G enters $1bn strategic partnership with Enosis Capital

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • US gasoline prices to rise after attack on Iran, analysts warn

    0 shares
    Share 0 Tweet 0

Latest News

Woman pleads not guilty to attempted murder of singer Rihanna

Woman pleads not guilty to attempted murder of singer Rihanna

March 26, 2026
0

Woman pleads not guilty to attempted murder of singer Rihanna

Stablecoins and the battle for monetary influence

What infrastructure do companies use to add stablecoin payments?

March 26, 2026
0

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes...

What Happens Now That Meta and YouTube Were Found Legally Negligent

What Happens Now That Meta and YouTube Were Found Legally Negligent

March 26, 2026
0

Mark Zuckerberg leaving Los Angeles Superior Court last month. Credit: Jon Putman/Anadolu via Getty Images On Wednesday, a Los Angeles...

Bryan Johnson: Psychedelics may revolutionize anti-aging, psilocybin enhances neuroplasticity for mental health, and the default mode network’s role in cognitive rejuvenation

Bryan Johnson: Psychedelics may revolutionize anti-aging, psilocybin enhances neuroplasticity for mental health, and the default mode network’s role in cognitive rejuvenation

March 26, 2026
0

Key Takeaways Psychedelics are being explored as potential rejuvenation protocols for anti-aging. Research on psilocybin indicates it may have significant...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.