{"id":727537,"date":"2023-05-10T13:11:37","date_gmt":"2023-05-10T15:11:37","guid":{"rendered":"https:\/\/teknomers.com\/fr\/des-experts-detaillent-la-nouvelle-vulnerabilite-windows-sans-clic-pour-le-vol-dinformations-didentification-ntlm\/"},"modified":"2023-05-10T13:11:40","modified_gmt":"2023-05-10T15:11:40","slug":"des-experts-detaillent-la-nouvelle-vulnerabilite-windows-sans-clic-pour-le-vol-dinformations-didentification-ntlm","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/des-experts-detaillent-la-nouvelle-vulnerabilite-windows-sans-clic-pour-le-vol-dinformations-didentification-ntlm\/","title":{"rendered":"Des experts d\u00e9taillent la nouvelle vuln\u00e9rabilit\u00e9 Windows sans clic pour le vol d&#8217;informations d&#8217;identification NTLM"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">10 mai 2023<\/span><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><\/span><span class=\"p-tags\">Vuln\u00e9rabilit\u00e9 \/ Windows<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><\/div>\n<p>Les chercheurs en cybers\u00e9curit\u00e9 ont partag\u00e9 des d\u00e9tails sur une faille de s\u00e9curit\u00e9 d\u00e9sormais corrig\u00e9e dans Windows <a rel=\"nofollow noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Trident_(software)\" target=\"_blank\">Plateforme MSHTML<\/a> qui pourraient \u00eatre abus\u00e9s pour contourner les protections d&#8217;int\u00e9grit\u00e9 sur les machines cibl\u00e9es.<\/p>\n<p>La vuln\u00e9rabilit\u00e9, suivie comme <a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-29324\" target=\"_blank\">CVE-2023-29324<\/a> (score CVSS : 6,5), a \u00e9t\u00e9 d\u00e9crit comme un contournement de fonction de s\u00e9curit\u00e9.  Il a \u00e9t\u00e9 trait\u00e9 par Microsoft dans le cadre de ses mises \u00e0 jour Patch Tuesday pour mai 2023.<\/p>\n<p>Le chercheur en s\u00e9curit\u00e9 d&#8217;Akamai, Ben Barnea, qui a d\u00e9couvert et signal\u00e9 le bogue, a not\u00e9 que toutes les versions de Windows sont affect\u00e9es, mais a soulign\u00e9 que Microsoft, Exchange <\/p>\n<p>les serveurs avec la mise \u00e0 jour de mars omettent la fonctionnalit\u00e9 vuln\u00e9rable.<\/p>\n<div class=\"ad_two clear\"><center class=\"cf\"><a rel=\"nofollow noopener\" href=\"https:\/\/thn.news\/tr60percentstatic-inside-1\" target=\"_blank\" title=\"Cybersecurity\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"La cyber-s\u00e9curit\u00e9\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2023\/05\/1683731497_110_Des-experts-detaillent-la-nouvelle-vulnerabilite-Windows-sans-clic-pour.png\" width=\"728\" height=\"90\"\/><\/a><\/center><\/div>\n<p>&#8220;Un attaquant non authentifi\u00e9 sur Internet pourrait utiliser la vuln\u00e9rabilit\u00e9 pour contraindre un client Outlook \u00e0 se connecter \u00e0 un serveur contr\u00f4l\u00e9 par l&#8217;attaquant&#8221;, a d\u00e9clar\u00e9 Barnea. <a rel=\"nofollow noopener\" href=\"https:\/\/www.akamai.com\/blog\/security-research\/important-outlook-vulnerability-bypass-windows-api\" target=\"_blank\">a dit<\/a> dans un rapport partag\u00e9 avec The Hacker News.<\/p>\n<p>&#8220;Cela entra\u00eene un vol d&#8217;informations d&#8217;identification NTLM. Il s&#8217;agit d&#8217;une vuln\u00e9rabilit\u00e9 sans clic, ce qui signifie qu&#8217;elle peut \u00eatre d\u00e9clench\u00e9e sans interaction de l&#8217;utilisateur.&#8221;<\/p>\n<p>Il convient \u00e9galement de noter que CVE-2023-29324 est un contournement d&#8217;un correctif que Microsoft a mis en place en mars 2023 pour r\u00e9soudre <a rel=\"nofollow noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-23397\" target=\"_blank\">CVE-2023-23397<\/a>une faille critique d&#8217;escalade de privil\u00e8ges dans Outlook qui, selon la soci\u00e9t\u00e9, a \u00e9t\u00e9 exploit\u00e9e par des acteurs mena\u00e7ants russes dans des attaques visant des entit\u00e9s europ\u00e9ennes depuis avril 2022.<\/p>\n<div class=\"ad_two clear\" style=\"margin: 20px 10px 30px 0;background: rgb(249 251 255);color: rgb(22, 7, 85);padding: 0px 5%;border: 2px solid rgb(217 222 255);border-radius: 10px;text-align: left;box-shadow: 10px 10px 0 #e2ebff;border-top-left-radius: 50px;border-bottom-right-radius: 50px;\"> <span style=\"font-size:14px;margin:25px 0 0 0;font-weight:900;background: #dbdefc;display:inline-block;padding: 3px 20px;border-radius: 100px;letter-spacing: 0.5px;color: #596cec;\">WEBINAIRE \u00c0 VENIR<\/span><\/p>\n<p>Apprenez \u00e0 arr\u00eater les ransomwares avec une protection en temps r\u00e9el<\/p>\n<p style=\"text-align:left;font-size:17px;line-height:30px;margin: 10px 0;color: #4e6a8d;\">Rejoignez notre webinaire et d\u00e9couvrez comment arr\u00eater les attaques de ransomwares dans leur \u00e9lan gr\u00e2ce \u00e0 la MFA en temps r\u00e9el et \u00e0 la protection des comptes de service.<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/thn.news\/silver-web-inside\" target=\"_blank\" style=\"padding: 10px 20px;border-radius: 8px;background-color: #4469f5;font-size:16px;display:inline-block;color:#fff;border:0;line-height:inherit;text-decoration:none;cursor:pointer;MARGIN: 10px 0 25px 0;float:left;font-weight:500;letter-spacing: 0.2px;\">Sauvez ma place\u00a0!<\/a><\/div>\n<p>Akamai a d\u00e9clar\u00e9 que le probl\u00e8me d\u00e9coulait de <a rel=\"nofollow noopener\" href=\"https:\/\/googleprojectzero.blogspot.com\/2016\/02\/the-definitive-guide-on-win32-to-nt.html\" target=\"_blank\">gestion complexe des chemins sous Windows<\/a>permettant ainsi \u00e0 un pirate de cr\u00e9er une URL malveillante qui peut contourner les v\u00e9rifications de la zone de s\u00e9curit\u00e9 Internet.<\/p>\n<p>&#8220;Cette vuln\u00e9rabilit\u00e9 est un autre exemple d&#8217;examen des correctifs conduisant \u00e0 de nouvelles vuln\u00e9rabilit\u00e9s et contournements&#8221;, a d\u00e9clar\u00e9 Barnea.  &#8220;Il s&#8217;agit d&#8217;une surface d&#8217;attaque d&#8217;analyse multim\u00e9dia sans clic qui pourrait potentiellement contenir des vuln\u00e9rabilit\u00e9s critiques de corruption de m\u00e9moire.&#8221;<\/p>\n<p>Afin de rester enti\u00e8rement prot\u00e9g\u00e9, Microsoft recommande en outre aux utilisateurs d&#8217;installer les mises \u00e0 jour cumulatives d&#8217;Internet Explorer pour r\u00e9soudre les vuln\u00e9rabilit\u00e9s de la plate-forme MSHTML et du moteur de script.<\/p>\n<p><\/p>\n<div class=\"cf note-b\">Vous avez trouv\u00e9 cet article int\u00e9ressant ?  Suivez-nous sur <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/thehackersnews\" target=\"_blank\">Twitter <i class=\"icon-font icon-twitter\">\uf099<\/i><\/a>  et <a rel=\"nofollow noopener\" href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" target=\"_blank\">LinkedIn<\/a> pour lire plus de contenu exclusif que nous publions.<\/div>\n<\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2023\/05\/experts-detail-new-zero-click-windows.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\ue80210 mai 2023\ue804Ravie LakshmananVuln\u00e9rabilit\u00e9 \/ Windows Les chercheurs en cybers\u00e9curit\u00e9 ont partag\u00e9 des d\u00e9tails sur une faille de s\u00e9curit\u00e9 d\u00e9sormais corrig\u00e9e dans Windows Plateforme MSHTML qui pourraient \u00eatre abus\u00e9s pour contourner les protections d&#8217;int\u00e9grit\u00e9 sur les machines cibl\u00e9es. La vuln\u00e9rabilit\u00e9, suivie comme CVE-2023-29324 (score CVSS : 6,5), a \u00e9t\u00e9 d\u00e9crit comme un contournement de fonction [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":727538,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[17155,4168,4158,4165,4161,133,38951,71695,22908,692,4157,4159,4171,4170,4167,4160,197,4163,4162,80875,185,1181,4172,4169,4166,1976,3667,4164,45020],"class_list":["post-727537","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-clic","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-des","tag-detaillent","tag-didentification","tag-dinformations","tag-experts","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelle","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-ntlm","tag-pour","tag-sans","tag-securite-informatique","tag-securite-internet","tag-violation-de-donnees","tag-vol","tag-vulnerabilite","tag-vulnerabilite-logicielle","tag-windows"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/727537","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=727537"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/727537\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/727538"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=727537"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=727537"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=727537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}