CVE-2023-23397
About
Microsoft Outlook Elevation of Privilege Vulnerability
Rainforest analyst review
There’s no link to click and no attachment to open. The attacker sends an Outlook email — a meeting or task with a reminder — and sets the reminder sound to a UNC path pointing at a server they control. When Outlook processes the reminder, it tries to fetch that sound file and hands over the victim’s Net-NTLMv2 authentication hash to the attacker’s server. The email triggering this before the user even reads it is what makes it zero-click.
That hash can be relayed to authenticate as the victim or cracked offline — either way the attacker gains the user’s identity without ever touching their password. It’s been tied to state-sponsored activity against government and critical-infrastructure targets: quiet, reliable, high-value. Patching Outlook is the fix, but because the trigger is inbound and automatic, also block outbound SMB (port 445) at the perimeter and consider forcing Kerberos, so a missed patch doesn’t hand credentials to the first crafted message that arrives.
References
Related CVEs
Frequently asked questions
What is CVE-2023-23397?
Microsoft Outlook Elevation of Privilege Vulnerability
How severe is CVE-2023-23397?
CVE-2023-23397 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2023-23397 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2023-23397?
Public advisories list the following as affected: 365 apps, office, office long term servicing channel, outlook. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2023-23397?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
