← Vulnerability feed

Vulnerability record · CVE-2023-35311 · published 11 July 2023

CVE-2023-35311: Microsoft Outlook security feature bypass via TOCTOU race condition

Microsoft · 365 Apps

CVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects Microsoft 365 Apps, Office, Office Long Term Servicing Channel, and Outlook. Because it bypasses a security feature, it can undermine protections that users and administrators rely on to block malicious content.

8.8 CVSS 3.1 High CISA KEV since 11 Jul 2023 EPSS 16% · top 3.3% CWE-367 · TOCTOU race condition
8.8CVSS 3.1 base score
16%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Microsoft Outlook Security Feature Bypass Vulnerability

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in the CISA KEV catalog with known exploitation, has a high CVSS score of 8.8, and affects widely deployed Microsoft Outlook and Office products.

What it is

CVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects Microsoft 365 Apps, Office, Office Long Term Servicing Channel, and Outlook. Because it bypasses a security feature, it can undermine protections that users and administrators rely on to block malicious content.

Impact

An attacker can bypass an Outlook security feature, which may allow malicious content or actions that the feature was meant to prevent. The CVSS vector indicates high confidentiality, integrity, and availability impact, though the record does not specify the exact protected mechanism.

Attack surface

The vulnerability is network-reachable (AV:N) with low attack complexity (AC:L) and no privileges required (PR:N), but it requires user interaction (UI:R). This is consistent with a crafted email or Outlook item that the user must open or interact with.

Exploitation

CISA added CVE-2023-35311 to the Known Exploited Vulnerabilities catalog on 2023-07-11, indicating exploitation in the wild. EPSS gives a 30-day exploitation probability of 0.15522 (96.6th percentile), and the record does not document ransomware campaign use.

What to do

  • Apply the Microsoft security updates referenced in the MSRC advisory for Outlook and affected Office products.
  • If patching is not immediately possible, follow CISA guidance to discontinue use of the affected product or apply compensating controls.
  • Prioritize patching for internet-facing and email-handling systems, especially where Outlook is used to open untrusted messages.
  • Review and tighten email filtering and attachment handling to reduce delivery of crafted messages that could trigger the bypass.
  • Monitor vendor advisories for updated guidance and any revised affected product lists.

Detection

  • Hunt for Outlook process behavior that deviates from normal after opening email or attachments, such as unexpected child processes or file writes.
  • Correlate endpoint telemetry for TOCTOU-style race patterns in Outlook, including rapid file or registry access sequences around message rendering.
  • Monitor for exploitation indicators published by Microsoft and CISA, and alert on known malicious message characteristics if available.
  • Audit patch levels for Outlook and Office products against the MSRC advisory to identify unpatched endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-35311 to the Known Exploited Vulnerabilities catalog on 11 July 2023 as "Microsoft Outlook Security Feature Bypass Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 1 August 2023.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-35311 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-21413Microsoft Outlook improper input validation remote code executionCVE-2024-21413 is a critical remote code execution flaw in Microsoft Outlook caused by improper input validation, tracked publicly as the MonikerLink…KEVEPSS 95%analysed9.8CVE-2023-23397Microsoft Outlook improper input validation privilege escalationCVE-2023-23397 is a critical elevation of privilege flaw in Microsoft Outlook caused by improper input validation and an authentication bypass by cap…KEVEPSS 97%analysed8.8CVE-2024-38189Microsoft Project Remote Code Execution via Improper Input ValidationMicrosoft Project and related Office products contain a remote code execution flaw rooted in improper input validation. An attacker can trigger code …KEVEPSS 8.2%analysed8.8CVE-2019-1297Microsoft Excel memory handling flaw allows remote code executionCVE-2019-1297 is a remote code execution vulnerability in Microsoft Excel caused by improper handling of objects in memory. An attacker who convinces…KEVEPSS 22%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2018-0798Microsoft Office Equation Editor memory corruption RCEEquation Editor in Microsoft Office 2007 through 2016 mishandles objects in memory, producing an out-of-bounds write (CWE-787) that can be turned int…KEVEPSS 95%analysed8.8CVE-2015-2424Microsoft Office memory corruption via crafted documentCVE-2015-2424 is an out-of-bounds write (CWE-787) in Microsoft PowerPoint and Word that is triggered when a crafted Office document is opened. A remo…KEVEPSS 40%analysed8.8CVE-2015-1770Microsoft Office uninitialized memory use allows remote code executionMicrosoft Office 2013 SP1 and 2013 RT SP1 mishandle uninitialized memory when parsing a crafted Office document, which can lead to arbitrary code exe…KEVEPSS 35%analysed

Source: NIST National Vulnerability Database (record CVE-2023-35311), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.