CVE-2023-23397CISA KEV
Microsoft Office Outlook Privilege Escalation Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
- Product
- Office
- Added to KEV
- 14 Mar 2023
- Federal remediation due
- 4 Apr 2023
- Known ransomware use
- Not reported