{"id":325930,"date":"2024-02-06T15:16:58","date_gmt":"2024-02-06T14:16:58","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=325930"},"modified":"2024-08-08T19:11:31","modified_gmt":"2024-08-08T17:11:31","slug":"microsoft-investiga-un-problema-de-seguridad-que-podria-revelar-las-contrasenas-de-los-usuarios","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/es\/microsoft-investiga-un-problema-de-seguridad-que-podria-revelar-las-contrasenas-de-los-usuarios\/","title":{"rendered":"Microsoft investiga un problema de seguridad que podr\u00eda revelar las contrase\u00f1as de los usuarios"},"content":{"rendered":"\n<p><strong>Microsoft<\/strong> ha informado de un aviso de seguridad en <strong>Outlook<\/strong> que se produce tras instalar las actualizaciones de seguridad publicadas en diciembre. Denominado <a href=\"https:\/\/support.microsoft.com\/en-us\/office\/outlook-prompts-security-notice-opening-ics-files-after-installing-protections-for-microsoft-outlook-information-disclosure-vulnerability-released-dec-12-2023-df8647ef-1828-421b-a266-79120b6190bd\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\"><strong>CVE-2023-35636<\/strong><\/a>, este problema est\u00e1 catalogado como importante y <strong>podr\u00eda permitir la revelaci\u00f3n de hashes NTLM<\/strong> (encargados de almacenar <a href=\"https:\/\/www.softonic.com\/articulos\/expressvpn-lanza-oficialmente-una-herramienta-total-de-gestion-de-contrasenas\">contrase\u00f1as<\/a> en los dispositivos), aunque su explotaci\u00f3n por ciberdelincuentes es poco probable.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/e7c83350-96d9-11e6-af79-00163ed833e7\/2296076294\/microsoft-365-icon.png\" alt=\"Microsoft 365\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Microsoft 365<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/microsoft-365.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DESCARGAR<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/microsoft-365.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p>Seg\u00fan recoge <strong><a href=\"https:\/\/windowsreport.com\/microsoft-outlook-security-vulnerability-that-could-reveal-your-windows-passwords\/\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">Windows Report<\/a><\/strong>, el error se produce al <strong>hacer clic en un archivo .ICS<\/strong>, apareciendo el siguiente mensaje: \u201cMicrosoft Office ha identificado un posible problema de seguridad. Es posible que esta ubicaci\u00f3n no sea segura\u201d. Sin embargo, <strong>el aviso de seguridad o la vulnerabilidad en s\u00ed no suponen una amenaza<\/strong> a menos que abras un archivo espec\u00edfico procedente de un atacante.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"350\" height=\"231\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/2\/2024\/02\/Aviso-seguridad-Microsoft-Office-060224.jpg\" alt=\"\" class=\"wp-image-325936\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2024\/02\/Aviso-seguridad-Microsoft-Office-060224.jpg 350w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2024\/02\/Aviso-seguridad-Microsoft-Office-060224-300x198.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2024\/02\/Aviso-seguridad-Microsoft-Office-060224-150x99.jpg 150w\" sizes=\"auto, (max-width: 350px) 100vw, 350px\" \/><\/figure>\n<\/div>\n\n\n<p>Microsoft tambi\u00e9n ha publicado una recomendaci\u00f3n sobre c\u00f3mo dejar de recibir este mensaje, cambiando una clave del registro. Para ello, los usuarios deben abrir el <strong>Editor del Registro<\/strong> (busc\u00e1ndolo en la barra de b\u00fasqueda) y dirigirse a la siguiente ruta (sin las comillas): &#8220;HKEY_CURRENT_USER\\software\\policies\\microsoft\\office\\16.0\\common\\security&#8221;. Una vez ah\u00ed, debemos buscar el DWORD <strong>\u201cDisableHyperlinkWarning\u201d<\/strong> y cambiar su valor a 1.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/e7c83350-96d9-11e6-af79-00163ed833e7\/2296076294\/microsoft-365-icon.png\" alt=\"Microsoft 365\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Microsoft 365<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/microsoft-365.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DESCARGAR<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/microsoft-365.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p>Eso s\u00ed, hay que tener en cuenta que al cambiar este DWORD en el registro, <strong>se desactivar\u00e1n todas las advertencias de seguridad de <a href=\"https:\/\/www.softonic.com\/articulos\/microsoft-office-como-saber-que-version-tengo\">Microsoft Office<\/a><\/strong>, no solo la de los archivos .ICS. Microsoft es consciente de este problema y afirma que lo solucionar\u00e1 en una futura actualizaci\u00f3n.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft ha informado de un aviso de seguridad en Outlook que se produce tras instalar las actualizaciones de seguridad publicadas en diciembre. Denominado CVE-2023-35636, este problema est\u00e1 catalogado como importante y podr\u00eda permitir la revelaci\u00f3n de hashes NTLM (encargados de almacenar contrase\u00f1as en los dispositivos), aunque su explotaci\u00f3n por ciberdelincuentes es poco probable. Seg\u00fan recoge &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/es\/microsoft-investiga-un-problema-de-seguridad-que-podria-revelar-las-contrasenas-de-los-usuarios\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Microsoft investiga un problema de seguridad que podr\u00eda revelar las contrase\u00f1as de los usuarios&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9256,"featured_media":325937,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[9317],"tags":[9918,9518,9367,9364],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-325930","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-app-subdomain-redirectionmicrosoft-365","tag-fallo-de-seguridad","tag-microsoft-office","tag-outlook"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts\/325930","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/users\/9256"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/comments?post=325930"}],"version-history":[{"count":0,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts\/325930\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/media\/325937"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/media?parent=325930"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/categories?post=325930"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/tags?post=325930"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/usertag?post=325930"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/vertical?post=325930"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/content-category?post=325930"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}