LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-23397: Microsoft Office Outlook Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 14, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 4, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-23397 to its Known Exploited Vulnerabilities catalog on Mar 14, 2023, with a federal patch deadline of Apr 4, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.

CVE-2023-23397 is a privilege escalation vulnerability in Microsoft Office Outlook. It enables an attacker to perform an NTLM Relay attack against another service and authenticate as the targeted user. For IT and security teams this matters because successful abuse can let an adversary impersonate users and reach resources that trust NTLM authentication, expanding access inside the environment. Confirm all product-specific details against the vendor advisory.

CISA lists the required action as applying updates per vendor instructions. Public detail on ransomware use is not documented for this CVE.

How it works

The weakness is classified as CWE-294. In Microsoft Office Outlook this manifests as a privilege-escalation path that permits an NTLM Relay attack. An attacker can cause the client to initiate an authentication exchange that is then relayed to another service, allowing the attacker to authenticate as the user whose credentials are being relayed. The CISA summary states that the vulnerability “allows for a NTLM Relay attack against another service to authenticate as the user.” Exact trigger conditions, message formats, or client-side behaviors are not provided here; treat any deeper exploit description as incomplete and verify against the official Microsoft advisory. The result is elevation of the attacker’s effective privileges to those of the victim user on the relayed service.

Am I affected? How to find it in your systems

Microsoft Office Outlook is the affected component; it typically runs on Windows endpoints used by knowledge workers, on terminal servers, and in virtual desktop environments that include the Office suite. Inventory all systems that have Microsoft Office installed, focusing on those that run Outlook. Check installed versions and configurations against the ranges listed in the vendor advisory—do not rely on version numbers that are not stated in that advisory. Look for Outlook clients that process external messages or calendar items, as those are common interaction points for this class of flaw.

For detection of possible exploitation, review authentication logs on domain controllers and on services that accept NTLM. Signs consistent with NTLM Relay activity include unexpected NTLM authentication attempts from client IP addresses, authentication to services that the user does not normally access, or sudden spikes in NTLM traffic. Correlate these with Outlook process activity or message-processing events if endpoint telemetry is available. Because the vulnerability is privilege-escalation via relay, successful abuse may appear as legitimate user authentication rather than an obvious exploit signature.

How to remediate

Patch first. Apply the updates Microsoft has released for this vulnerability, following the instructions in the vendor advisory. CISA’s required action is exactly that: apply updates per vendor instructions. After patching, verify that the update is present on every Outlook-equipped system through your patch-management or inventory tooling.

Additional hardening for this class of issue includes reducing reliance on NTLM where possible, enforcing SMB signing and channel-binding for services that still accept NTLM, and reviewing Outlook security settings that control how external content and calendar invitations are handled. These steps limit the usefulness of a successful relay even if an unpatched client remains briefly online.

If you can't patch immediately

Until the vendor update can be deployed, apply compensating controls. Segment Outlook clients from high-value services that accept NTLM authentication so that a relayed credential cannot reach them. Consider temporary virtual patching or network filtering that blocks the specific traffic patterns associated with the attack class, provided the filter is validated against the vendor’s description. Disable or restrict the Outlook features that process unsolicited external messages or calendar items if business needs allow. Increase monitoring of NTLM authentication events and alert on anomalous relays or authentications originating from Outlook processes. These measures reduce the attack surface and improve detection while the permanent fix is rolled out.

If your data may have been exposed

Actively exploited vulnerabilities can lead to credential theft and subsequent data breaches. If you suspect that NTLM credentials were relayed, treat the affected accounts as compromised: reset passwords, revoke sessions, and review access logs for unauthorized activity. You can run a free exposure scan of your email addresses against known breach data sets to determine whether those addresses already appear in public breach collections; that check is independent of this CVE but helps establish overall exposure posture.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Office
WeaknessCWE-294
Added to CISA KEVMar 14, 2023
Federal patch deadlineApr 4, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities