CVE-2023-23397 Details
Description
Microsoft Outlook Elevation of Privilege Vulnerability
A vulnerability allowing elevation of privilege has been identified in Microsoft Outlook. This issue arises from improper input validation, which can be exploited to perform an NTLM Relay attack. Such an attack would allow an attacker to authenticate as a user on another service by relaying the user's Net-NTLMv2 hash, potentially leading to unauthorized access or actions.
Users are advised to apply the security updates provided by Microsoft. For more information, consult the Microsoft Security Update Guide.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 21, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-23397 | CISA-ADP | US Government Resource |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397 | CVE | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397 | [email protected] | PatchVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Microsoft Office Outlook Privilege Escalation Vulnerability | Mar 14, 2023 | Apr 4, 2023 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-294 | Authentication Bypass by Capture-replay | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft 365 apps | All versions |
CPE
Remediation
| |
| microsoft office | 2019 |
CPE
Remediation
| |
| microsoft office long term servicing channel | 2021 |
CPE
Remediation
| |
| microsoft outlook | 2013 sp1 2016 |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Oct 27, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 13, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Aug 14, 2024 | Modified Analysis | [email protected] |
| May 29, 2024 | CVE Modified | [email protected] |
| May 28, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Mar 20, 2023 | Initial Analysis | [email protected] |