WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Threat Awareness – Outlook Calendar Invite Vulnerability Can Steal Passwords with One Click
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – Outlook Calendar Invite Vulnerability Can Steal Passwords with One Click

Author: Chase Snow

Created: Tuesday, January 23, 2024 - 19:11

Categories: Cybersecurity

Outlook is a near ubiquitous communications application. Additionally, with so many social engineering/phishing tactics targeting users through their inboxes, vulnerabilities left unpatched often become an attractive threat vector. One of three Microsoft vulnerabilities recently disclosed by Varonis has the ability to steal hashed passwords through Outlook’s calendar invitation with just one click. This vulnerability was assigned CVE-2023-35636 and Microsoft distributed the patch on December 12, 2023. However, according to Varonis, two additional vulnerabilities remain that have not been addressed by the Redmond giant.

In the Outlook vulnerability, the attacker takes advantage of the Outlook calendar’s invitation function. When a user accepts the malicious invitation, Outlook shares the calendar details between the two computers and it’s in this process that the hashed passwords can be leaked. Essentially, all three vulnerabilities described by Varonis are leveraged to steal NTLM v2 hashes, but the Outlook calendar function has been classified as the most severe.

According to Varonis, there are two more vulnerabilities leveraged to steal NTLM v2 hashes worth noting. These include Windows Performance Analyzer (WPA), and Windows File Explorer (WFE). However, they do require more user interaction and Microsoft stated they do not consider them vulnerabilities and did not create a patch.

To protect against NTLM hash brute-force, systems administrators may wish to consider employing Kerberos for authentication instead of Microsoft’s NTLM v2. Kerberos authentication reduces the risk from brute-forcing hashed passwords. Additionally, keep patches and updates current. For more details, access SC Magazine or Varonis.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 7, 2026)

May 7, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:GREEN) Gate 15 TARGET Report – Identity Centric Attacks: The Shift from Network to Identity as the Primary Attack Surface

May 7, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) CISA and Partners Release Guidance for Careful Adoption of Agentic AI Services

May 7, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar