CVE-2018-0950 flaw in Microsoft Outlook could be exploited to steal Windows Passwords

“Here we can see than an SMB connection is being automatically negotiated. The only action that triggers this negotiation is Outlook previewing an email that is sent to it.” The following screenshot shows that IP address, domain name, Username, hostname, SMB session key are being leaked.

Read full news article on Security Affairs


