Junglewise Threat Intelligence

CVE-2023-23397: Microsoft Office Outlook Privilege Escalation Vulnerability

CVE-2023-23397 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-03-14

Technologies: Microsoft Office, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

Microsoft Outlook contains an elevation of privilege vulnerability that allows for NTLM relay attacks. An attacker can trigger the vulnerability by sending a specially crafted email that causes the client to automatically connect to an attacker-controlled SMB share, leaking NTLM credentials without user interaction.

Affected products

  • Microsoft Outlook 2013 Service Pack 1
  • Microsoft Outlook 2016
  • Microsoft Office 2019
  • Microsoft Office LTSC 2021
  • Microsoft Microsoft 365 Apps for Enterprise

Timeline

  • 2023-03-14: disclosed
  • 2023-03-14: patched
  • 2023-03-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-03-14: exploited: Reported as exploited in the wild at time of publication.

Related threats