ZeroHour

CVE-2023-23397

KEVmass2

Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak)

CISA: Microsoft Office Outlook Privilege Escalation Vulnerability

CVSS 3.1
9.8 critical
EPSS
97%p100
Published
()
KEV added
AI analysis

CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates.

What to do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook.

Affected
Microsoft 365 AppsAffected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
Microsoft OfficeAffected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
Microsoft Office Long Term Servicing Channel (LTSC)Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
Microsoft OutlookAffected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
Estimated exposure
masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite) — Because Outlook is bundled with Microsoft Office and Microsoft 365, whose install base runs to hundreds of millions of users worldwide, and because exploitation needs only a crafted email to reach a mailbox, plausibly affected exposure is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Outlook Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Office
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
365 apps, office, office long term servicing channel, outlook
Weakness
CWE-20, CWE-294
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news