vendor:
Microsoft Office
by:
Metin Yunus Kandemir
6.1
CVSS
HIGH
Hash Disclosure
200
CWE
Product Name: Microsoft Office
Affected Version From: Microsoft Office 2019 MSO Build 1808 (16.0.10411.20011), Microsoft 365 MSO (Version 2403 Build 16.0.17425.20176)
Affected Version To: Not specified
Patch Exists: NO
Related CWE: CVE-2024-38200
CPE: a:microsoft:office:2019
Platforms Tested: Windows 11
2024
Microsoft Office 2019 MSO Build 1808 – NTLMv2 Hash Disclosure
The exploit involves abusing MS Office URI schemes to fetch a document from a remote source. By invoking a specific URI scheme on a victim computer, an attacker can capture and relay NTLMv2 hash over SMB and HTTP.
Mitigation:
To mitigate this vulnerability, restrict the use of MS Office URI schemes and ensure that users do not execute or interact with unknown or suspicious URIs.