ZeroHour

CVE-2023-35311

KEVmass1

TOCTOU Security Feature Bypass in Microsoft Outlook (Exploited in the Wild)

CISA: Microsoft Outlook Security Feature Bypass Vulnerability

CVSS 3.1
8.8 high
EPSS
16%p97
Published
()
KEV added
AI analysis

CVE-2023-35311 is a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) in Microsoft Outlook that allows a security feature to be bypassed. It is triggered remotely over the network when a user interacts with a specially crafted email; per Microsoft's advisory, the attacker needs to know the target's mailbox email address. Successful exploitation defeats Outlook's security check (scored high for confidentiality and integrity impact), lowering the barrier for follow-on actions such as malware delivery via email content. The flaw affects Outlook as delivered with Microsoft 365 Apps, Office, and Office LTSC. It is confirmed exploited in the wild (added to CISA KEV on 2023-07-11) and was fixed in Microsoft's July 2023 Patch Tuesday; no public proof-of-concept is known.

What to do: Apply the July 2023 Patch Tuesday security updates (released July 11, 2023) for Outlook, Office, Microsoft 365 Apps, and Office LTSC as soon as possible, since the flaw is being exploited in the wild and is on CISA's KEV list (U.S. civilian agency deadline August 1, 2023). After patching, verify Outlook and Office build numbers reflect the July 2023 updates, and review mailboxes for suspicious emails that users interacted with around the security prompt. Ransomware use is unknown, so treat any unpatched internet-active mail clients as priority targets in patch cycles.

Affected
Microsoft OutlookBuilds prior to the July 11, 2023 Patch Tuesday security updates
Microsoft 365 AppsBuilds prior to the July 11, 2023 Patch Tuesday security updates
Microsoft OfficeBuilds prior to the July 11, 2023 Patch Tuesday security updates
Microsoft Office Long Term Servicing Channel (LTSC)Builds prior to the July 11, 2023 Patch Tuesday security updates
Estimated exposure
masshundreds of millions of Outlook users worldwide — Outlook is the default desktop mail client bundled with Microsoft 365 and Office, whose installed base spans hundreds of millions of enterprise and consumer seats, so effectively all unpatched desktop Outlook deployments are potentially…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Outlook Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Outlook
Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
365 apps, office, office long term servicing channel, outlook
Weakness
CWE-367
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news