Sale of a 1-day exploit for Microsoft Outlook

Dark Web2026-09-08, 09:26
For informational purposes only.
The attack scenario involves using a phishing email containing a link to a remote resource (for example, an image). When the message is opened in the preview pane, the client initiates a network request to load the resource. When attempting to connect to the requested resource, the OS automatically provides the current user's credentials (username and NTLM hash) for authentication.
According to the seller, the exploit affects CVE-2023-23397, CVE-2024-21413, CVE-2024-30103, CVE-2024-26194, CVE-2023-35311.
Affected operating systems: Windows 10, Windows 11, Windows 8.1, Windows 7, Windows Server Price: $10K
Vulnerabilities
10
CVE-2023-23397
10
CVE-2023-35311
10
CVE-2024-21413
7.4
CVE-2024-26194
More
Researchers
Haifei Li
Arnold Osipov
Michael Gorelik
Shmuel Uzan
Vendors
Microsoft
Products
Microsoft Outlook
Windows 10
Windows 11
Windows 7
Windows 8.1
Windows Server