CVE-2023-35311
KEVmass1TOCTOU Security Feature Bypass in Microsoft Outlook (Exploited in the Wild)
CISA: Microsoft Outlook Security Feature Bypass Vulnerability
CVE-2023-35311 is a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) in Microsoft Outlook that allows a security feature to be bypassed. It is triggered remotely over the network when a user interacts with a specially crafted email; per Microsoft's advisory, the attacker needs to know the target's mailbox email address. Successful exploitation defeats Outlook's security check (scored high for confidentiality and integrity impact), lowering the barrier for follow-on actions such as malware delivery via email content. The flaw affects Outlook as delivered with Microsoft 365 Apps, Office, and Office LTSC. It is confirmed exploited in the wild (added to CISA KEV on 2023-07-11) and was fixed in Microsoft's July 2023 Patch Tuesday; no public proof-of-concept is known.
What to do: Apply the July 2023 Patch Tuesday security updates (released July 11, 2023) for Outlook, Office, Microsoft 365 Apps, and Office LTSC as soon as possible, since the flaw is being exploited in the wild and is on CISA's KEV list (U.S. civilian agency deadline August 1, 2023). After patching, verify Outlook and Office build numbers reflect the July 2023 updates, and review mailboxes for suspicious emails that users interacted with around the security prompt. Ransomware use is unknown, so treat any unpatched internet-active mail clients as priority targets in patch cycles.
| Microsoft Outlook | Builds prior to the July 11, 2023 Patch Tuesday security updates |
| Microsoft 365 Apps | Builds prior to the July 11, 2023 Patch Tuesday security updates |
| Microsoft Office | Builds prior to the July 11, 2023 Patch Tuesday security updates |
| Microsoft Office Long Term Servicing Channel (LTSC) | Builds prior to the July 11, 2023 Patch Tuesday security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Outlook Security Feature Bypass Vulnerability
- Affected
- Microsoft Outlook
- Required action
- Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- 365 apps, office, office long term servicing channel, outlook
- Weakness
- CWE-367
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H