Microsoft Office Outlook
CVE-2023-23397 — Microsoft Outlook Elevation of Privilege Vulnerability
Executive Summary
None
Overview
9.8
CVSS CRITICAL
Critical
MS Severity
Exploited
MS Exploit Status
Exploitation Detected
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Functional
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 9.1
EPSS Score
0.97408
probability of exploitation in the next 30 days
0.99893 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
11 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Microsoft 365 Apps for Enterprise for 32-bit Systems | Click to Run (Security Update) |
Critical | Elevation of Privilege | No |
| Microsoft 365 Apps for Enterprise for 64-bit Systems | Click to Run (Security Update) |
Critical | Elevation of Privilege | No |
| Microsoft Office 2019 for 32-bit editions | Click to Run (Security Update) |
Critical | Elevation of Privilege | No |
| Microsoft Office 2019 for 64-bit editions | Click to Run (Security Update) |
Critical | Elevation of Privilege | No |
| Microsoft Office LTSC 2021 for 32-bit editions | Click to Run (Security Update) |
Critical | Elevation of Privilege | No |
| Microsoft Office LTSC 2021 for 64-bit editions | Click to Run (Security Update) |
Critical | Elevation of Privilege | No |
| Microsoft Outlook 2013 RT Service Pack 1 | 5002265 (Security Update) |
Critical | Elevation of Privilege | Maybe |
| Microsoft Outlook 2013 Service Pack 1 (32-bit editions) | 5002265 (Security Update) |
Critical | Elevation of Privilege | Maybe |
| Microsoft Outlook 2013 Service Pack 1 (64-bit editions) | 5002265 (Security Update) |
Critical | Elevation of Privilege | Maybe |
| Microsoft Outlook 2016 (32-bit edition) | 5002254 (Security Update) |
Critical | Elevation of Privilege | Maybe |
| Microsoft Outlook 2016 (64-bit edition) | 5002254 (Security Update) |
Critical | Elevation of Privilege | Maybe |
Patches
3 patches
| Article | Type | Restart |
|---|---|---|
Click to Run |
Security Update | No |
5002265 |
Security Update | Maybe |
5002254 |
Security Update | Maybe |
Exploits & PoC
15 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| api0cradle/CVE-2023-23397-POC-Powershell | 346 | 2023-03-16 | |
| sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAY | 158 | 2023-03-15 | Exploit for the CVE-2023-23397 |
| Trackflaw/CVE-2023-23397 | 132 | 2023-03-20 | Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email. |
| ka7ana/CVE-2023-23397 | 40 | 2023-03-16 | Simple PoC in PowerShell for CVE-2023-23397 |
| tiepologian/CVE-2023-23397 | 25 | 2023-03-21 | Proof of Concept for CVE-2023-23397 in Python |
| Muhammad-Ali007/OutlookNTLM_CVE-2023-23397 | 22 | 2023-07-14 | |
| BronzeBee/cve-2023-23397 | 14 | 2023-03-22 | Python script for sending e-mails with CVE-2023-23397 payload using SMTP |
| djackreuter/CVE-2023-23397-PoC | 9 | 2023-03-18 | |
| vlad-a-man/CVE-2023-23397 | 8 | 2023-05-07 | CVE-2023-23397 PoC |
| BillSkiCO/CVE-2023-23397_EXPLOIT | 7 | 2023-03-17 | Generates meeting requests taking advantage of CVE-2023-23397. This requires the outlook thick client to send. |
| ahmedkhlief/CVE-2023-23397-POC | 6 | 2023-03-17 | Exploit POC for CVE-2023-23397 |
| grn-bogo/CVE-2023-23397 | 4 | 2023-03-16 | Python script to create a message with the vulenrability properties set |
| Pushkarup/CVE-2023-23397 | 4 | 2023-10-26 | This script exploits CVE-2023-23397, a Zero-Day vulnerability in Microsoft Outlook, allowing the generation of malicious emails for testing and educational purposes. |
| alicangnll/CVE-2023-23397 | 3 | 2023-03-16 | CVE-2023-23397 - Microsoft Outlook Vulnerability |
| P4x1s/CVE-2023-23397-POC | 3 | 2023-03-31 | CVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。 |
Detection Rules
Detection availableCommunity detection & vulnerability-scanning rules aggregated from Sigma and Nuclei templates. Validate and tune to your environment before deploying.
Sigma rules 4
Acknowledgments
CERT-UA, Microsoft Incident Response, Microsoft Threat Intelligence
References
On This Page