Vulnerability record · CVE-2023-35311 · published 11 July 2023
CVE-2023-35311: Microsoft Outlook security feature bypass via TOCTOU race condition
Microsoft · 365 Apps
CVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects Microsoft 365 Apps, Office, Office Long Term Servicing Channel, and Outlook. Because it bypasses a security feature, it can undermine protections that users and administrators rely on to block malicious content.
Description
Microsoft Outlook Security Feature Bypass Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in the CISA KEV catalog with known exploitation, has a high CVSS score of 8.8, and affects widely deployed Microsoft Outlook and Office products.
What it is
CVE-2023-35311 is a security feature bypass in Microsoft Outlook caused by a time-of-check time-of-use (TOCTOU) race condition (CWE-367). It affects Microsoft 365 Apps, Office, Office Long Term Servicing Channel, and Outlook. Because it bypasses a security feature, it can undermine protections that users and administrators rely on to block malicious content.
Impact
An attacker can bypass an Outlook security feature, which may allow malicious content or actions that the feature was meant to prevent. The CVSS vector indicates high confidentiality, integrity, and availability impact, though the record does not specify the exact protected mechanism.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity (AC:L) and no privileges required (PR:N), but it requires user interaction (UI:R). This is consistent with a crafted email or Outlook item that the user must open or interact with.
Exploitation
CISA added CVE-2023-35311 to the Known Exploited Vulnerabilities catalog on 2023-07-11, indicating exploitation in the wild. EPSS gives a 30-day exploitation probability of 0.15522 (96.6th percentile), and the record does not document ransomware campaign use.
What to do
- Apply the Microsoft security updates referenced in the MSRC advisory for Outlook and affected Office products.
- If patching is not immediately possible, follow CISA guidance to discontinue use of the affected product or apply compensating controls.
- Prioritize patching for internet-facing and email-handling systems, especially where Outlook is used to open untrusted messages.
- Review and tighten email filtering and attachment handling to reduce delivery of crafted messages that could trigger the bypass.
- Monitor vendor advisories for updated guidance and any revised affected product lists.
Detection
- Hunt for Outlook process behavior that deviates from normal after opening email or attachments, such as unexpected child processes or file writes.
- Correlate endpoint telemetry for TOCTOU-style race patterns in Outlook, including rapid file or registry access sequences around message rendering.
- Monitor for exploitation indicators published by Microsoft and CISA, and alert on known malicious message characteristics if available.
- Audit patch levels for Outlook and Office products against the MSRC advisory to identify unpatched endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-35311 to the Known Exploited Vulnerabilities catalog on 11 July 2023 as "Microsoft Outlook Security Feature Bypass Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 1 August 2023.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35311 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35311 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-35311 | US Government Resource |
Track CVE-2023-35311 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-35311), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.