CVE-2023-23397General(microsoft / 365_apps)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft 365_apps systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Outlook Elevation of Privilege Vulnerability

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-04-04. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-20CWE-294

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 365_apps
  • office
  • office_long_term_servicing_channel
  • outlook

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 16 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 9 signals
  • General: 8 classified signals
  • Peaked 13d ago at 2 mentions (2026-03-02); latest day: 1
  • 17 total mentions across 16 days

Affected systems

Vendors
Products
365_appsofficeoffice_long_term_servicing_channeloutlook

5 versions affected across 4 products

Deep dive

Activity timeline17 mentions / 16d
01122Mentions · 2026-01-28: 1Mentions · 2026-02-12: 1Mentions · 2026-03-02: 2Mentions · 2026-03-04: 1Mentions · 2026-03-10: 1Mentions · 2026-03-20: 1Mentions · 2026-03-27: 1Mentions · 2026-04-18: 1Mentions · 2026-05-01: 1Mentions · 2026-05-03: 1Mentions · 2026-05-04: 1Mentions · 2026-06-10: 1Mentions · 2026-06-17: 1Mentions · 2026-06-23: 1Mentions · 2026-06-30: 1Mentions · 2026-10-08: 1PoC Mentioned / Linked · 2026-06-23: 1Exploit Tool / Code · 2026-06-23: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-02-12: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-04: 1Active Exploitation · 2026-06-17: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-05-04: 1Technical Details · 2026-02-12: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-10: 1Technical Details · 2026-05-01: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-17: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-30: 101-2802-1203-0203-0403-1003-2003-2704-1805-0105-0305-0406-1006-1706-2306-3010-08
Signal classification5 categories
General
850.0%
Active Exploitation
531.3%
PoC
16.3%
Disclose
16.3%
Disclosure
16.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-01-281
Active Exploitation1
2026-02-121
Active Exploitation1
2026-03-022
General2
2026-03-041
General1
2026-03-101
PoC1
2026-03-201
General1
2026-03-271
General1
2026-04-181
General1
2026-05-011
Active Exploitation1
2026-05-031
General1
2026-05-041
Active Exploitation1
2026-06-101
General1
2026-06-171
Active Exploitation1
2026-06-231
Disclose1
2026-06-301
Disclosure1
Full discourse17 posts
  • OS Dev@OSdev_
    Disclose

    CVE-2023-23397 is a critical Elevation of Privilege (EoP) vulnerability in Microsoft Outlook for Windows, with a CVSS score of 9.8 The attacker sends a crafted message containing an extended MAPI property (like a meeting reminder sound) that directs the victim's machine to a Universal Naming Convention (UNC) path on an attacker-controlled SMB or WebDAV server. https://github.com/Trackflaw/CVE-2023-23397

    Post summary

    The passage announces a high‑severity elevation‑of‑privilege flaw in Outlook, provides technical details and a GitHub link to a PoC, but contains no indication of active exploitation or patches.

    018082444.7K
    4.8K followersView on X
  • XINTRA@XintraOrg
    General

    NEW LAB: Global Freight UA 🚛 We emulated a CISA report on APT28/Russian GRU targeting Ukrainian logistics . This lab is packed with IoT compromise, CCTV and surveillance platform access with: - Outlook / CVE-2023-23397 forced authentication - HEADLACE-style staging + DLL sideloading - AD CS abuse + certificate-based privilege escalation - CCTV, IoT and camera compromise - Anti-forensics techniques Contributors @ZephrFish @r3nzsec Solve it here 👇 https://xintra.org

    Post summary

    This text describes a lab that emulates APT28 targeting Ukrainian logistics, referencing CVE-2023-23397 and other techniques, but it does not provide evidence of a PoC, exploitation, or patches.

    26129125.8K
    5.4K followersView on X
  • OS Dev@OSdev_
    Disclosure

    CVE-2023-23397 is an Outlook privilege escalation vulnerability that doesn't rely on macros or opening an email. A specially crafted message can trigger Outlook to automatically retrieve a remote resource, causing Windows to authenticate with the attacker's server via NTLM. The leaked NTLM hash can then be relayed to authenticate as the victim. It's an excellent case study in Outlook internals, MAPI properties, NTLM authentication, and credential relay attacks.

    Post summary

    The post announces key details about CVE-2023-23397, explaining how a specially crafted Outlook message triggers NTLM authentication to allow credential relay, but it does not mention PoC code, active exploitation, or patches.

    1101881.3K
    5.0K followersView on X
  • Hackron@Hackr0n
    Active Exploitation

    Francia atribuye 12 ciberataques al GRU ruso (APT28/Fancy Bear): ministerios, defensa, aeroespacial y #ParísOlímpico. Vector: phishing + zero-day CVE-2023-23397. +4k ataques rusos en 2k4 (+15%). Fuente: @BleepingComputer En #Hackron conoce CERTS de Ref https://www.eventbrite.es/e/entradas-hackron-2026-1984927736292 https://t.co/WmAGQfh3RP

    Post summary

    The tweet reports 12 cyberattacks by the Russian GRU targeting French ministries, defense, aerospace and the Paris Olympics, using a zero‑day CVE‑2023‑23397 in phishing campaigns, confirming active exploitation but providing no PoC, patch, or detailed exploit.

    02020202
    4.4K followersView on X
  • Inferlume@inferlume_hq
    Active Exploitation

    APT28 used the same technique against CVE-2023-23397 in Outlook. Same TTP, new delivery path. CISA KEV confirmed. Microsoft MSTIC and FortiGuard both corroborate. Federal patch deadline is May 12.

    Post summary

    APT28 is actively exploiting CVE-2023-23397 in Outlook, confirmed by CISA KEV and corroborated by Microsoft MSTIC and FortiGuard, with a federal patch deadline set for May 12.

    1000059
    1 followersView on X
  • 無重力トレーニング@acupunc28094787
    General

    I just completed Outlook NTLM Leak room on TryHackMe! Leak password hashes from a user by sending them an email by abusing CVE-2023-23397. https://tryhackme.com/room/outlookntlmleak?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=65869e2abbbd1398b6caad7d #tryhackme via @tryhackme

    Post summary

    The user describes completing a TryHackMe room that demonstrates leaking NTLM password hashes via CVE‑2023‑23397, but provides no additional PoC, exploit, patch, or technical detail.

    0001091
    96 followersView on X
  • Justin Elze@HackingLZ
    General

    @ImposeCost Russia - CVE-2023-23397

    Post summary

    The tweet only references CVE‑2023‑23397 in relation to Russia, with no further details or actionable information.

    00010355
    69.2K followersView on X
  • David@davidsheyi
    General

    2/ Example: For CVE-2023-23397, study lateral movement paths. This aids in crafting rules that detect step-by-step intrusions. #InfoSec #Detection

    Post summary

    The post uses CVE-2023-23397 as a case study for teaching lateral movement detection but provides no technical details, exploitation evidence, or remediation guidance.

    1000069
    555 followersView on X
  • David@davidsheyi
    General

    1/ APT29, attributed to Russia, is known for its sophisticated spear-phishing campaigns. They often exploit vulnerabilities like CVE-2023-23397. Stay vigilant. #APT #NationState

    Post summary

    The post references CVE-2023-23397 in the context of APT29's exploitation but offers no technical details, PoC, or evidence of active attacks.

    1000073
    556 followersView on X
  • JTCrawford@JtCrawford
    Active Exploitation

    Russia's APT28 just exploited a 0-day in Outlook (CVE-2023-23397) to compromise 30+ Ukrainian critical infrastructure targets. No user interaction needed—just opening the email triggers NTLM hash theft. Patch NOW. #CyberSecurity #ThreatIntel #APT28 https://t.co/U5igpAvbF2

    Post summary

    The tweet reports that APT28 exploited CVE-2023-23397 in Outlook, affecting over 30 Ukrainian critical infrastructure targets via NTLM hash theft without user interaction, and urges immediate patching.

    00010194
    24 followersView on X
  • David@davidsheyi
    Active Exploitation

    3/ IABs often exploit known vulnerabilities like CVE-2023-23397, which was leveraged to gain initial access in recent high-profile attacks. Always patch! #Vulnerability #InfoSec

    Post summary

    The tweet claims CVE-2023-23397 was used in recent high‑profile attacks and urges patches, but offers no technical details or exploit code.

    10000105
    557 followersView on X
  • DailyCVE@dailycve

    🔴 #Microsoft Outlook, Elevation of Privilege, #CVE-2023-23397 (Critical) -DC-Oct2026-2886 https://dailycve.com/microsoft-outlook-elevation-of-privilege-cve-2023-23397-critical-dc-oct2026-2886/

    000009
    239 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Rapid7 reported that Microsoft Exchange Server CVE-2020-16875 and Microsoft Outlook CVE-2023-23397 are under active exploitation, enabling authenticated RCE and NTLM relay attacks against affected organisations. https://threatcluster.io/cluster/microsoft-exchange-vulnerabilities-cve-2020-16875-and-cve-20-1688ca3b

    Post summary

    Rapid7 reports active exploitation of CVE-2020-16875 and CVE-2023-23397, enabling authenticated RCE and NTLM relay attacks on affected organizations, with no mention of mitigation or PoC code.

    00000152
    356 followersView on X
  • Sun4lower@LittleSun4lower
    General

    I just completed Outlook NTLM Leak room on TryHackMe! Leak password hashes from a user by sending them an email by abusing CVE-2023-23397. https://tryhackme.com/room/outlookntlmleak?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #Learning #Consistency

    Post summary

    The user reports completing a TryHackMe lab that demonstrates how CVE-2023‑23397 can be abused to leak password hashes by sending a malicious email, with no additional technical details or real‑world exploitation claims.

    0000084
    5 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    PoC

    I just completed Outlook NTLM Leak room on TryHackMe! Leak password hashes from a user by sending them an email by abusing CVE-2023-23397. https://tryhackme.com/room/outlookntlmleak?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The post highlights a TryHackMe lab that demonstrates abusing CVE‑2023‑23397 to exfiltrate NTLM hashes via email, but it does not provide code, patch notes, or evidence of real‑world exploitation.

    0000052
  • Audn AI@audn_ai
    General

    🛡️ PenTest tip: explore CVE-2023-23397 – Windows Print Spooler remote code execution vulnerability. Use it as a sandbox exercise to sharpen your exploit‑development skills. #PenTesting #CVE CVE-2023-23397 (ref:1772486730705) 😃 I love digging into real‑world exploits!

    Post summary

    The post provides a general pen‑testing tip to practice exploitation of CVE‑2023‑23397, mentioning the vulnerability type but not offering PoC, exploit code, or patch details.

    000002
    12 followersView on X
  • Audn AI@audn_ai
    General

    🛡️ PenTest tip: explore CVE-2023-23397 – Windows Print Spooler remote code execution vulnerability. Use it as a sandbox exercise to sharpen your exploit‑development skills. #PenTesting #CVE CVE-2023-23397 (ref:1772486007470) 😃 I love digging into real‑world exploits!

    Post summary

    The tweet encourages a PenTest exercise on CVE‑2023‑23397, mentioning it as a Windows Print Spooler RCE but providing no PoC, exploit, patch, or active‑use details.

    000001
    12 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoft365_apps---
Appmicrosoftoffice2019--
Appmicrosoftoffice_long_term_servicing_channel2021--
Appmicrosoftoutlook2013--
Appmicrosoftoutlook2013--
Appmicrosoftoutlook2016--

Explore more