PT-2023-1662 · Microsoft · Outlook

CVE-2023-23397

·

Published

2023-03-14

·

Updated

2026-09-08

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Outlook (affected versions not specified)
Description An elevation of privilege issue exists where a remote attacker can gain higher privileges by sending a specially crafted email. The flaw does not require user interaction, such as opening the email or enabling macros, as the payload is triggered automatically when the Outlook client retrieves and processes the message. Technically, the vulnerability allows the attacker to force Outlook to automatically retrieve a remote resource, which causes Windows to authenticate with the attacker's server using NTLM (New Technology LAN Manager, a suite of Microsoft security protocols). This process leaks the NTLM hash, which can then be relayed to authenticate as the victim. This issue has been actively exploited by the threat actor APT28 (also known as Forest Blizzard, STRONTIUM, or FANCYBEAR).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

LPE

RCE

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01214
CVE-2023-23397

Affected Products

Outlook