CVE-2023-23397
9.8CRITICALMicrosoft Outlook Elevation of Privilege Vulnerability
Publicado: 3/14/2023Atualizado: 10/27/2025
Vulnerabilidade Explorada Conhecida (CISA)
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
Ação Necessária:
Apply updates per vendor instructions.
Prazo:
2023-04-04
Descrição
Microsoft Outlook Elevation of Privilege Vulnerability
Análise IADesenvolvido por IA
Produtos Afetados
microsoft365_apps
-
microsoftoffice
2019
microsoftoffice_long_term_servicing_channel
2021
microsoftoutlook
2013
microsoftoutlook
2013
microsoftoutlook
2016
Referências
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397PatchVendor Advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397PatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-23397US Government Resource