CVE-2023-23397: Microsoft Office Outlook Privilege Escalation
Microsoft Office Outlook Privilege Escalation Vulnerability. Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
- CISA KEV-listed (remediation due 2023-04-04)
- EPSS 97.4% (99.9% percentile)
- CVSS 9.8 critical
Detection rules
- Outlook Task/Note Reminder Received low
- CVE-2023-23397 Exploitation Attempt critical
- Potential CVE-2023-23397 Exploitation Attempt - SMB medium
- Suspicious WebDav Client Execution Via Rundll32.EXE high
Related briefings
Linked threat actors
- APT28 machine-inferred link