CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
Other sources
Microsoft Outlook Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5387.1000Patch KB5002254 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5537.1000Patch KB5002265
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-23397?
CVE-2023-23397 is a privilege escalation vulnerability in Microsoft Office Outlook.
What is the severity of CVE-2023-23397?
CVE-2023-23397 has a severity level of critical.
How does CVE-2023-23397 affect Microsoft Office Outlook?
CVE-2023-23397 allows for an NTLM Relay attack against another service to authenticate as the user.
Which versions of Microsoft Office are affected by CVE-2023-23397?
Microsoft Office versions including Office 2019, Office 365 Apps for Enterprise, and Office LTSC 2021 are affected by CVE-2023-23397.
How can I mitigate CVE-2023-23397 in Microsoft Office Outlook?
To mitigate CVE-2023-23397, apply the security updates provided by Microsoft for the affected versions of Microsoft Office Outlook.