← Vulnerability feed

Vulnerability record · CVE-2023-23397 · published 14 March 2023

CVE-2023-23397: Microsoft Outlook improper input validation privilege escalation

Microsoft · 365 Apps

CVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by capture-replay. It matters because it allows an unauthenticated attacker to trigger the vulnerability remotely with no user interaction, and it is listed in CISA's Known Exploited Vulnerabilities catalog.

9.8 CVSS 3.1 Critical CISA KEV since 14 Mar 2023 EPSS 97% · top 0.1% CWE-20 · Improper input validationCWE-294 · Authentication bypass by capture-replay
9.8CVSS 3.1 base score
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Microsoft Outlook Elevation of Privilege Vulnerability

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, active exploitation confirmed by CISA KEV, and very high EPSS probability make this an urgent patching priority.

What it is

CVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by capture-replay. It matters because it allows an unauthenticated attacker to trigger the vulnerability remotely with no user interaction, and it is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

An attacker can gain the same privileges as the targeted user or service account, potentially leading to full compromise of the affected system. The CVSS vector indicates high confidentiality, integrity, and availability impact.

Attack surface

The vulnerability is reachable over the network (AV:N) with no privileges required (PR:N) and no user interaction (UI:N), meaning an attacker can exploit it by sending a crafted message or connection to an Outlook client. No authentication is needed.

Exploitation

CISA added this CVE to the KEV catalog on 2023-03-14 with a remediation due date of 2023-04-04, confirming active exploitation in the wild. EPSS gives a 30-day exploitation probability of 0.97408 (99.896th percentile), indicating very high likelihood of exploitation.

What to do

  • Apply the vendor patches listed in the Microsoft Security Response Center advisory immediately.
  • Follow CISA KEV required actions and ensure remediation by the due date.
  • Restrict network exposure of Outlook clients and block unnecessary inbound connections where feasible.
  • Monitor for and investigate suspicious Outlook-related network traffic or authentication attempts.
  • Review and harden service accounts and privileges that could be abused after exploitation.

Detection

  • Monitor for unusual outbound network connections from Outlook processes to untrusted hosts.
  • Audit authentication logs for replay or anomalous authentication events involving Outlook or related services.
  • Use endpoint detection to flag exploitation attempts targeting Outlook input validation flaws.
  • Track CISA KEV and vendor advisories for updated indicators of compromise.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-23397 to the Known Exploited Vulnerabilities catalog on 14 March 2023 as "Microsoft Office Outlook Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 4 April 2023.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-23397 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21413Microsoft Outlook improper input validation remote code executionCVE-2024-21413 is a critical remote code execution flaw in Microsoft Outlook caused by improper input validation, tracked publicly as the MonikerLink…KEVEPSS 95%analysed8.8CVE-2024-38189Microsoft Project Remote Code Execution via Improper Input ValidationMicrosoft Project and related Office products contain a remote code execution flaw rooted in improper input validation. An attacker can trigger code …KEVEPSS 8.2%analysed8.8CVE-2023-35311Microsoft Outlook security feature bypass via TOCTOU race conditionCVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects …KEVEPSS 16%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2015-1770Microsoft Office uninitialized memory use allows remote code executionMicrosoft Office 2013 SP1 and 2013 RT SP1 mishandle uninitialized memory when parsing a crafted Office document, which can lead to arbitrary code exe…KEVEPSS 35%analysed

Source: NIST National Vulnerability Database (record CVE-2023-23397), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.