Outlook NTLM Leak
Outlook NTLM Leak CVE-2023-23397
Tools: Responder, Outlook Appointment Alerts, OutlookSpy Plugin
Affects all version of the Outlook desktop app on any Windows System.
Exploit method: Zero-click
Explanation:
Abusing reminder sounds via UNC paths (Universal Naming Convention)
Payload example:
2 and 3 examples are alternatives to SMB protocol that use HTTP and HTTPS to retrieve the file from a WebDAV enabled webserver.
Exploitation:
Detection:
Mitigation:
Last updated