Microsoft has fixed an issue that triggers erroneous Outlook security alerts when opening .ICS calendar files after installing the December 2023 Outlook Desktop security updates. The December Patch Tuesday security updates behind these inaccurate warnings patch the CVE-2023-35636 Microsoft Outlook information disclosure vulnerability, which attackers can exploit to steal NTLM hashes via maliciously crafted files. These credentials are used to authenticate as the compromised Windows user in pass-the-hash attacks, to gain access to sensitive data or spread laterally on their network. Microsoft 365 users impacted by this issue see dialog boxes warning them that "Microsoft Office has identified a potential security concern" and that "This location may be unsafe" when double-clicking ICS files saved locally. "This behavior is not expected when opening .ICS files. This is a bug and will be addressed in a future update," the Outlook Team said in February when Microsoft first acknowledged this known issue. Microsoft has now found a fix for this issue and is shipping it with Outlook for Microsoft 365 Version 2404 Build 17531.20000 in the Beta Channel. Those affected can test the fix if they're in the Office Insider Channels. Current Channel users can expect to receive a fix for the issue on April 30th. Once the fix has been tested in production, it will be backported to Version 2402 for the Semi-Annual Enterprise Channel (Preview) during the June 2024 Patch Tuesday. Until the fix is ...
Microsoft fixes Outlook security alerts bug caused by December updates
BleepingComputer
·Sergiu Gatlan
·Published Apr 4, 2024
·Updated
Affected Software
2 affected components
Microsoft Outlook=365 Version 2404 Build 17531.20000
Microsoft Outlook=365 Version 2402
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Microsoft addressing a bug in Outlook that caused incorrect security alerts when opening .ICS calendar files after the December 2023 updates.
2
What security implications are discussed?
The article highlights how the erroneous security alerts could potentially confuse users and affect their trust in Outlook's security measures.
3
What products or software are affected?
The bug affects Microsoft Outlook 365 versions 2404 Build 17531.20000 and 2402.
4
What was the trigger for the security alerts issue?
The issue was triggered by the December 2023 Patch Tuesday security updates for Outlook.
5
How has Microsoft resolved the issue?
Microsoft has released fixes to eliminate the erroneous security alerts in Outlook caused by the updates.