CVE-2023-23397
KEVmass2Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak)
CISA: Microsoft Office Outlook Privilege Escalation Vulnerability
CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates.
What to do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook.
| Microsoft 365 Apps | Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges |
| Microsoft Office | Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges |
| Microsoft Office Long Term Servicing Channel (LTSC) | Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges |
| Microsoft Outlook | Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Outlook Elevation of Privilege Vulnerability
- Affected
- Microsoft Office
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- 365 apps, office, office long term servicing channel, outlook
- Weakness
- CWE-20, CWE-294
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H