Feb. 14, 2024, 1:55 a.m. | /u/Andrew0275

cybersecurity www.reddit.com

There is a new critical CVE for Microsoft Outlook: [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413)

Is this another case of CVE-2023-23397 of last year where there is a critical need to patch?

So far the attack description seems pretty vague, and there is not much more info about it. It does mention it can "lead to the leakage of local NTLM credential information", which seems pretty critical but its still hard to say without at least a proof-of-concept. Thoughts?

attack can case credential critical cve cve-2023-23397 cybersecurity far hard info information local ntlm patch

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)