Executive brief
Microsoft Outlook contains an elevation of privilege vulnerability that allows for NTLM relay attacks. An attacker can trigger the vulnerability by sending a specially crafted email that causes the client to automatically connect to an attacker-controlled SMB share, leaking NTLM credentials without user interaction.
Affected products
- Microsoft Outlook 2013 Service Pack 1
- Microsoft Outlook 2016
- Microsoft Office 2019
- Microsoft Office LTSC 2021
- Microsoft Microsoft 365 Apps for Enterprise
Timeline
- 2023-03-14: disclosed
- 2023-03-14: patched
- 2023-03-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-03-14: exploited: Reported as exploited in the wild at time of publication.