Microsoft Alert
9507Warning Date
Severity Level
Warning Number
Target Sector
15 March, 2023
● Critical
2023-5507
All
Microsoft has released security updates to address several vulnerabilities in the following products:
- Windows Server 2022
- Windows Server 2019
- Windows Server 2016
- Windows Server 2012
- Windows Server 2008
- Windows 11
- Windows 10
- Microsoft Outlook 2016
- Microsoft Outlook 2013
- Microsoft Office 2019
- Microsoft 365 Apps
- Microsoft Office LTSC 2021
An attacker could exploit these vulnerabilities by doing the following:
- Remote Code Execution
- Gain SYSTEM privileges
- Security feature bypass
- Steal Net-NTLMv2 hash by sending a specially crafted email to the Outlook client
- Denial-of-service (DoS)
The CERT team encourages users to review Microsoft security advisory and apply the necessary updates: