{"id":272737,"date":"2024-02-06T09:29:50","date_gmt":"2024-02-06T14:29:50","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=325930"},"modified":"2025-07-01T17:06:11","modified_gmt":"2025-07-02T00:06:11","slug":"microsoft-is-investigating-a-security-issue-that-could-reveal-users-passwords","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/microsoft-is-investigating-a-security-issue-that-could-reveal-users-passwords\/","title":{"rendered":"Microsoft is investigating a security issue that could reveal users&#8217; passwords"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Microsoft<\/strong> has reported a security advisory in <strong>Outlook<\/strong> that occurs after installing the security updates released in December. Known as <a href=\"https:\/\/support.microsoft.com\/en-us\/office\/outlook-prompts-security-notice-opening-ics-files-after-installing-protections-for-microsoft-outlook-information-disclosure-vulnerability-released-dec-12-2023-df8647ef-1828-421b-a266-79120b6190bd\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\"><strong>CVE-2023-35636<\/strong><\/a>, this issue is classified as important and <strong>could allow the disclosure of NTLM hashes<\/strong> (which store <a href=\"https:\/\/en.softonic.com\/articles\/expressvpn-officially-launches-a-total-password-management-tool\" target=\"_blank\" rel=\"noopener\" title=\"\">passwords<\/a> on devices), although its exploitation by cybercriminals is unlikely.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Microsoft 365\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/e7c83350-96d9-11e6-af79-00163ed833e7\/2296076294\/microsoft-365-icon.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Microsoft 365<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/microsoft-365.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/microsoft-365.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">According to <strong><a href=\"https:\/\/windowsreport.com\/microsoft-outlook-security-vulnerability-that-could-reveal-your-windows-passwords\/\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">Windows Report<\/a><\/strong>, the error occurs when <strong>clicking on a .ICS file<\/strong>, displaying the following message: &#8220;Microsoft Office has identified a potential security concern. This location may not be safe.&#8221; However, <strong>the security warning or vulnerability itself does not pose a threat<\/strong> unless you open a specific file from an attacker.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1091\" height=\"720\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2024\/02\/Aviso-seguridad-Microsoft-Office-060224.jpg\" alt=\"\" class=\"wp-image-272741\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/02\/Aviso-seguridad-Microsoft-Office-060224.jpg 1091w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/02\/Aviso-seguridad-Microsoft-Office-060224-300x198.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/02\/Aviso-seguridad-Microsoft-Office-060224-1024x676.jpg 1024w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/02\/Aviso-seguridad-Microsoft-Office-060224-768x507.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2024\/02\/Aviso-seguridad-Microsoft-Office-060224-150x99.jpg 150w\" sizes=\"auto, (max-width: 1091px) 100vw, 1091px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Microsoft has also published a recommendation on how to stop receiving this message by changing a registry key. To do this, users must open the <strong>Registry Editor<\/strong> (by searching for it in the search bar) and go to the following path (without the quotes): &#8220;HKEY_CURRENT_USERsoftwarepoliciesmicrosoftoffice16.0commonsecurity&#8221;. Once there, we must look for the DWORD <strong>\u201cDisableHyperlinkWarning\u201d<\/strong> and change its value to 1.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Microsoft 365\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/e7c83350-96d9-11e6-af79-00163ed833e7\/2296076294\/microsoft-365-icon.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Microsoft 365<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/microsoft-365.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/microsoft-365.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">However, it should be noted that by changing this DWORD in the registry, <strong>all security warnings from Microsoft Office will be disabled<\/strong>, not just those for .ICS files. Microsoft is aware of this issue and claims that it will be fixed in a future update.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has reported a security advisory in Outlook that occurs after installing the security updates released in December. Known as CVE-2023-35636, this issue is classified as important and could allow the disclosure of NTLM hashes (which store passwords on devices), although its exploitation by cybercriminals is unlikely. According to Windows Report, the error occurs when &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/microsoft-is-investigating-a-security-issue-that-could-reveal-users-passwords\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Microsoft is investigating a security issue that could reveal users&#8217; passwords&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9256,"featured_media":272739,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[1015],"tags":[2717,5224,1060,1057],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-272737","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionmicrosoft-365","tag-fallo-de-seguridad","tag-microsoft-office","tag-outlook"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/272737","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9256"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=272737"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/272737\/revisions"}],"predecessor-version":[{"id":314908,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/272737\/revisions\/314908"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/272739"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=272737"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=272737"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=272737"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=272737"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=272737"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=272737"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}