PT-2023-1662 · Microsoft · Outlook
CVE-2023-23397
·
Published
2023-03-14
·
Updated
2026-09-08
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook (affected versions not specified)
Description
An elevation of privilege issue exists where a remote attacker can gain higher privileges by sending a specially crafted email. The flaw does not require user interaction, such as opening the email or enabling macros, as the payload is triggered automatically when the Outlook client retrieves and processes the message. Technically, the vulnerability allows the attacker to force Outlook to automatically retrieve a remote resource, which causes Windows to authenticate with the attacker's server using NTLM (New Technology LAN Manager, a suite of Microsoft security protocols). This process leaks the NTLM hash, which can then be relayed to authenticate as the victim. This issue has been actively exploited by the threat actor APT28 (also known as Forest Blizzard, STRONTIUM, or FANCYBEAR).
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
LPE
RCE
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Outlook