From 9fc418583bfa693e8594d5db3d8dfdc9bc71e1d0 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Tue, 21 Mar 2023 12:05:31 -0600 Subject: [PATCH] Renamed story Outlook Elevation of Privilege --- detections/endpoint/windows_rundll32_webdav_request.yml | 2 +- .../windows_rundll32_webdav_with_network_connection.yml | 2 +- .../cve_2023_23397_pidlidreminder_privilege_escalation.yml | 4 ++-- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/detections/endpoint/windows_rundll32_webdav_request.yml b/detections/endpoint/windows_rundll32_webdav_request.yml index e568deadd2..72cc3a07df 100644 --- a/detections/endpoint/windows_rundll32_webdav_request.yml +++ b/detections/endpoint/windows_rundll32_webdav_request.yml @@ -24,7 +24,7 @@ references: - https://www.pwndefend.com/2023/03/15/the-long-game-persistent-hash-theft/ tags: analytic_story: - - CVE-2023-23397 PidLidReminder Privilege Escalation + - CVE-2023-23397 Outlook Elevation of Privilege asset_type: Endpoint cis20: - CIS 3 diff --git a/detections/experimental/endpoint/windows_rundll32_webdav_with_network_connection.yml b/detections/experimental/endpoint/windows_rundll32_webdav_with_network_connection.yml index a6049574c4..352952cd66 100644 --- a/detections/experimental/endpoint/windows_rundll32_webdav_with_network_connection.yml +++ b/detections/experimental/endpoint/windows_rundll32_webdav_with_network_connection.yml @@ -28,7 +28,7 @@ references: - https://www.pwndefend.com/2023/03/15/the-long-game-persistent-hash-theft/ tags: analytic_story: - - CVE-2023-23397 PidLidReminder Privilege Escalation + - CVE-2023-23397 Outlook Elevation of Privilege asset_type: Endpoint cis20: - CIS 3 diff --git a/stories/cve_2023_23397_pidlidreminder_privilege_escalation.yml b/stories/cve_2023_23397_pidlidreminder_privilege_escalation.yml index dae163fcf9..1a1b372dab 100644 --- a/stories/cve_2023_23397_pidlidreminder_privilege_escalation.yml +++ b/stories/cve_2023_23397_pidlidreminder_privilege_escalation.yml @@ -1,4 +1,4 @@ -name: CVE-2023-23397 PidLidReminder Privilege Escalation +name: CVE-2023-23397 Outlook Elevation of Privilege id: b459911b-551f-480f-a402-18cf89ca1e9c version: 1 date: '2023-03-15' @@ -14,7 +14,7 @@ references: - https://msrc.microsoft.com/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/ - https://www.pwndefend.com/2023/03/15/the-long-game-persistent-hash-theft/ tags: - analytic_story: CVE-2023-23397 PidLidReminder Privilege Escalation + analytic_story: CVE-2023-23397 Outlook Elevation of Privilege category: - Adversary Tactics product: