2 funny vulnerabilities (Edge CVE-2022-2623, Outlook CVE-2022-35742)

Опубликовано: 04 Ноябрь 2024
на канале: Alexander Leonov
73
1

Vulristics suddenly highlighted the Memory Corruption in Microsoft #Edge (CVE-2022-2623) vulnerability because there is a public exploit for it. It turned out that there was a bug in the exploit databases: 0day.today and packetstorm. CVE-2022-2623 was mistakenly written instead of CVE-2022-26233. And this also happens and no one checks it. Well, prioritization of vulnerabilities based on distorted source data does not work well.
Denial of Service – Microsoft #Outlook (CVE-2022-35742). This was reported through the ZDI program and is a mighty interesting bug. Sending a crafted email to a victim causes their Outlook application to terminate immediately. Outlook cannot be restarted. Upon restart, it will terminate again once it retrieves and processes the invalid message. It is not necessary for the victim to open the message or to use the Reading pane. The only way to restore functionality is to access the mail account using a different client (i.e., webmail, or administrative tools) and remove the offending email(s) from the mailbox before restarting Outlook.

Telegram: https://t.me/avleonovcom/1031
Blogpost: https://avleonov.com/2022/08/23/micro...