Mandiant: Dangerous MS Outlook zero-day widely used against Ukraine

Negro Elkha – stock.adobe.com

A zero-day vulnerability in Microsoft Outlook that was fixed in the March Patch Tuesday update has likely been actively exploited by Russian actors for a year or more, and its use will now spread rapidly

Alex Scroxton

By

Published: 16 Mar 2023 12:15

A serious elevation of privilege vulnerability in Microsoft Outlook, which was disclosed and patched earlier this week in Microsoft’s latest Patch Tuesday update, has likely been exploited by Russian state-backed threat actors against Ukrainian targets for at least 12 months.

John Hultquist, head of Google Mandiant Intelligence Analysis, said that following its public disclosure, he anticipated broad and rapid adoption of CVE-2023-23397 by multiple nation state and financially motivated actors, probably including ransomware gangs. In the coming days and weeks, he warned, these groups will be engaged in a race to exploit the vulnerability before it’s patched to gain a foothold in target systems. Computer Weekly understands that proof of concept exploits are already circulating.

“This is more evidence that aggressive, disruptive and destructive cyber attacks may not remain constrained to Ukraine and a reminder that we cannot see everything,” he said. “While preparation for attacks do not necessarily indicate they are imminent, the geopolitical situation should give us pause.

“This is also a reminder that we cannot see everything going on with this conflict. These are spies and they have a long track record of successfully evading our notice,” said Hultquist. “This will be a propagation event. This is an excellent tool for nation-state actors and criminals alike who will be on a bonanza in the short term. The race has already begun.”

Exploitation of CVE-2023-23397 begins by sending a specially crafted email to the victim, but because it’s triggered server-side, can be exploited before the email is opened and viewed.

This email will have been crafted with an extended Messaging Application Programming Interface property containing a Universal Naming Convention path to the Server Message Block (SMB) share on a server the attacker controls.

When this email is received, a connection opens to the attacker’s SMB share and the victim’s Windows New Technology LAN Manager authentication protocol sends a negotiation message. This in turn can be seen and used by the attacker to discover the victim’s Net-NTLMv2 hash, extract it, and relay it to other systems in the victim’s environment, authenticating to them as the compromised user without needing to be in possession of their credentials.

In this way, the attacker not only gains a foothold in their target environment, but is able to begin lateral movement. Mandiant considers it a high-risk vulnerability due to the fact it can be used to elevate privileges without user interaction.

It was discovered by the national Computer Emergency Response Team (CERT) of Ukraine, CERT-UA, alongside Microsoft researchers, and according to Mandiant, it has been widely exploited by Russia in the past year to target organisations and critical infrastructure in Ukraine, in the service of intelligence collection and disruptive and destructive attacks on the country.

Mandiant has also seen it being used in attacks on targets in the defence, government, oil and gas, logistics, and transportation sectors in Poland, Romania and Turkey.

Mandiant’s research team has created a new designation – UNC4697 – to track exploitation of the zero-day, which is being widely attributed to APT28, an advanced persistent threat group backed by Russia’s GRU intelligence agency, also known as Fancy Bear or Strontium. This is a high-profile threat actor previously implicated in Russian attacks on the International Olympic Committee and the US presidential elections of 2016 and 2020. It frequently works with GRU actor Sandworm.

Read more on Hackers and cybercrime prevention

Read More
Margarete Culton

Latest

The Truth About Red Light Therapy Masks, According to a Dermatologist

You don't have permission to access "http://www.medpagetoday.com/popmedicine/cultureclinic/120805" on this server. Reference #18.9751c317.1776352333.14d1e5c https://errors.edgesuite.net/18.9751c317.1776352333.14d1e5c

Do Stabilisation Admissions Support Eating Disorder Care?

TOPLINE: Among children and young individuals (aged 0-18 years) admitted for medical stabilisation of restrictive eating disorders, more than half continued their recovery through outpatient care; however, a notable proportion were medically unstable on admission, and many required nutritional support. METHODOLOGY: Researchers conducted a retrospective cohort analysis to evaluate outcomes of medical stabilisation admissions in

‘Not your parents’ cannabis:’ Legalization lights up innovation—but not clinical research

🛡️ Just a quick check We’re checking your connection to prevent automated abuse

NFL Analyst Raises Red Flags Over Arvell Reese’s Fit As Edge Rusher on PFSN’s Football Debate Club

As the 2026 NFL Draft approaches, few defensive prospects have generated as much intrigue as Ohio State’s Arvell Reese. Widely viewed as one of the most talented defenders in the class, Reese’s versatility has made him a standout on scouting boards. However, with that versatility comes an ongoing debate about how he projects at the

Newsletter

Don't miss

The Truth About Red Light Therapy Masks, According to a Dermatologist

You don't have permission to access "http://www.medpagetoday.com/popmedicine/cultureclinic/120805" on this server. Reference #18.9751c317.1776352333.14d1e5c https://errors.edgesuite.net/18.9751c317.1776352333.14d1e5c

Do Stabilisation Admissions Support Eating Disorder Care?

TOPLINE: Among children and young individuals (aged 0-18 years) admitted for medical stabilisation of restrictive eating disorders, more than half continued their recovery through outpatient care; however, a notable proportion were medically unstable on admission, and many required nutritional support. METHODOLOGY: Researchers conducted a retrospective cohort analysis to evaluate outcomes of medical stabilisation admissions in

‘Not your parents’ cannabis:’ Legalization lights up innovation—but not clinical research

🛡️ Just a quick check We’re checking your connection to prevent automated abuse

NFL Analyst Raises Red Flags Over Arvell Reese’s Fit As Edge Rusher on PFSN’s Football Debate Club

As the 2026 NFL Draft approaches, few defensive prospects have generated as much intrigue as Ohio State’s Arvell Reese. Widely viewed as one of the most talented defenders in the class, Reese’s versatility has made him a standout on scouting boards. However, with that versatility comes an ongoing debate about how he projects at the

Athena launches FabOrchestrator, an agentic AI platform for manufacturing execution systems

In short: Athena Technology Solutions, a Fremont-based MES integrator with roughly 120 employees, has launched FabOrchestrator, an agentic AI platform for manufacturing that automates reporting, support tickets, system modelling, and code generation for semiconductor and electronics factories. Built in partnership with Bangalore-based LLM at Scale.AI, it layers LLM capabilities on top of the Siemens Opcenter

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day

The Big Business of Carolyn Bessette-Kennedy

Can a nine-episode limited series really impact an entire season of shopping trends? Today brands are experiencing—and chasing—the “Carolyn Bessette-Kennedy effect” as a result of Ryan Murphy’s Love Story. And in many cases, it’s more pervasive than they could have prepared for. The FX series, based on the relationship between John F. Kennedy Jr. and

‘Mind Your Own Business’: Kamal Haasan Rebukes Trump Over ‘Permission’ To Buy Russian Oil

Updated 8 March 2026 at 18:20 IST Actor and Rajya Sabha MP Kamal Haasan has hit out at US President Donald Trump after America announced that it has given India temporary "permission" to buy Russian oil amid global supply disruptions caused by the Middle East conflict. 'Mind Your Own Business': Kamal Haasan Rebukes Trump Over