Vulnerability record · CVE-2023-23397 · published 14 March 2023
CVE-2023-23397: Microsoft Outlook improper input validation privilege escalation
Microsoft · 365 Apps
CVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by capture-replay. It matters because it allows an unauthenticated attacker to trigger the vulnerability remotely with no user interaction, and it is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
Microsoft Outlook Elevation of Privilege Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, active exploitation confirmed by CISA KEV, and very high EPSS probability make this an urgent patching priority.
What it is
CVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by capture-replay. It matters because it allows an unauthenticated attacker to trigger the vulnerability remotely with no user interaction, and it is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker can gain the same privileges as the targeted user or service account, potentially leading to full compromise of the affected system. The CVSS vector indicates high confidentiality, integrity, and availability impact.
Attack surface
The vulnerability is reachable over the network (AV:N) with no privileges required (PR:N) and no user interaction (UI:N), meaning an attacker can exploit it by sending a crafted message or connection to an Outlook client. No authentication is needed.
Exploitation
CISA added this CVE to the KEV catalog on 2023-03-14 with a remediation due date of 2023-04-04, confirming active exploitation in the wild. EPSS gives a 30-day exploitation probability of 0.97408 (99.896th percentile), indicating very high likelihood of exploitation.
What to do
- Apply the vendor patches listed in the Microsoft Security Response Center advisory immediately.
- Follow CISA KEV required actions and ensure remediation by the due date.
- Restrict network exposure of Outlook clients and block unnecessary inbound connections where feasible.
- Monitor for and investigate suspicious Outlook-related network traffic or authentication attempts.
- Review and harden service accounts and privileges that could be abused after exploitation.
Detection
- Monitor for unusual outbound network connections from Outlook processes to untrusted hosts.
- Audit authentication logs for replay or anomalous authentication events involving Outlook or related services.
- Use endpoint detection to flag exploitation attempts targeting Outlook input validation flaws.
- Track CISA KEV and vendor advisories for updated indicators of compromise.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-23397 to the Known Exploited Vulnerabilities catalog on 14 March 2023 as "Microsoft Office Outlook Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 4 April 2023.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-23397 | US Government Resource |
Track CVE-2023-23397 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-23397), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.