LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-35311: Microsoft Outlook Security Feature Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 11, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 1, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-35311 to its Known Exploited Vulnerabilities catalog on Jul 11, 2023, with a federal patch deadline of Aug 1, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.

CVE-2023-35311 is a security feature bypass vulnerability in Microsoft Outlook. It allows an attacker to bypass the Microsoft Outlook Security Notice prompt that normally warns users about potentially unsafe content or actions in email. This matters because the prompt is a key user-facing control intended to reduce the chance of opening or interacting with malicious messages; bypassing it can leave organizations more exposed to social-engineering and follow-on compromise if the vulnerability is successfully abused.

Defenders should treat this as a high-priority item for Outlook environments and confirm all technical details against the official Microsoft advisory before taking action.

How it works

The vulnerability is classified under CWE-367 and is described as a security feature bypass. In practical terms, an attacker can craft conditions that cause Outlook to skip or suppress the Security Notice prompt that would otherwise appear. The CISA summary states that this allows an attacker to bypass that specific notice.

No further exploit mechanics, payload formats, or race-condition details are provided in the available facts. Technical teams should assume that successful abuse removes a deliberate warning layer rather than granting direct remote code execution by itself. Confirm the precise trigger conditions and any required user interaction against the vendor advisory; do not rely on third-party write-ups that invent specifics.

Am I affected? How to find it in your systems

Microsoft Outlook is the affected product. It typically runs on Windows endpoints used by knowledge workers, on terminal servers or VDI images, and in some managed desktop environments. Inventory every installation of Outlook across workstations, virtual desktops, and any servers that host the client.

If you cannot map a given Outlook instance to a patched build, treat it as potentially affected until proven otherwise.

How to remediate

Patch first. Apply the updates Microsoft has released for this vulnerability exactly as described in the vendor advisory. The CISA required action is to apply updates per vendor instructions or to discontinue use of the product if updates are unavailable.

Document the remediation in your vulnerability-management system and retain evidence of the applied update for audit purposes.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls that limit the impact of a bypassed security notice.

These measures do not eliminate the vulnerability; they only buy time until the official update is applied.

If your data may have been exposed

Actively exploited vulnerabilities can lead to account compromise and subsequent data exposure even when ransomware use is not documented for this specific CVE. If you suspect successful abuse, treat any credentials or mailboxes that interacted with suspicious messages as potentially compromised: reset passwords, revoke tokens, and review mail-forwarding rules and OAuth consents. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether those addresses already appear in public dumps, then prioritize monitoring and credential hygiene accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Outlook
WeaknessCWE-367
Added to CISA KEVJul 11, 2023
Federal patch deadlineAug 1, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities