Executive brief
Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt. The flaw is related to a Time-of-check Time-of-use (TOCTOU) race condition (CWE-367).
Affected products
- Microsoft Outlook 2013 Service Pack 1
- Microsoft Outlook 2016
- Microsoft Office 2019
- Microsoft Office LTSC 2021
- Microsoft Microsoft 365 Apps for Enterprise
Timeline
- 2023-07-11: disclosed
- 2023-07-11: patched
- 2023-07-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-07-11: exploited: Reported as exploited in the wild at time of publication.