Hackers exploit "forced authentication" to steal Windows NTLM.

Cybersecurity researchers have discovered a case of “forced authentication,” exploiting a legitimate feature in a database management system that allows users to connect to external data sources. The goal of the attack is to leak a Windows user’s NT LAN Manager (NTLM) credentials , with the victim opening a specially crafted Microsoft Access file.
See more: North Korean hackers combine macOS malware tactics to evade detection
The attack begins when the victim opens an .accdb or .mdb file, with the hacker embedding a remote SQL Server database link into an MS Word document, using the Object Linking and Embedding (OLE) mechanism . The hackers' attack is dangerous, as it can leak NTLM hashes to a hacker-controlled server, thus bypassing traditional detection methods.
If the victim opens the file and clicks on the linked table, the victim server contacts the server controlled by the hacker. A relay attack is then performed, entering an authentication process with a selected server . Microsoft and 0patch have developed workarounds for the issue that occurs in various versions of Office/Access.
The development continues, as Microsoft announced its plans to replace NTLM with Kerberos in Windows 11 for increased security.

Read more: Hacking Attack or Student Prank in Lee County Schools?
Source: thehackernews.com
