CyberzSOC

Publication detail
← Back to advisories & guidance

2024-077: Vulnerabilities in Microsoft Office ↗ source

August 12, 2024 CERT-EU Advisory

Summary

This security flaw is caused by an information disclosure weakness that enables unauthorised actors to access The vulnerability CVE-2024-38200 (CVSS score: 7.5) is an information disclosure vulnerability that allows remote attackers to access NTLM hashes. Attackers can exploit this flaw via a specially crafted file or web-based attack, potentially leading to NTLM relay attacks or password According to Microsoft’s advisory, the following products are affected [4]: 1. Set the “Restrict NTLM: Outgoing NTLM traffic to remote servers” group policy to block NTLM traffic from computers running Windows 7, Windows Server 2008, or later to any 2. Add users to the Protected Users Security Group, which restricts NTLM as an authentication method [3]. 3. Block all outbound traffic on TCP port 445 to prevent NTLM traffic from leaving the CERT-EU recommends applying the mitigations provided by Microsoft [4], including blocking outbound NTLM traffic, while Microsoft releases the updates.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-38200 6.5 Medium Microsoft Microsoft Office 2019 Microsoft Office Spoofing Vulnerability

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.