Junglewise Threat Intelligence

CVE-2023-35311: Microsoft Outlook Security Feature Bypass Vulnerability

CVE-2023-35311 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-07-11

Executive brief

Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt. The flaw is related to a Time-of-check Time-of-use (TOCTOU) race condition (CWE-367).

Affected products

  • Microsoft Outlook 2013 Service Pack 1
  • Microsoft Outlook 2016
  • Microsoft Office 2019
  • Microsoft Office LTSC 2021
  • Microsoft Microsoft 365 Apps for Enterprise

Timeline

  • 2023-07-11: disclosed
  • 2023-07-11: patched
  • 2023-07-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-07-11: exploited: Reported as exploited in the wild at time of publication.

Related threats