CRITICAL

CVE-2023-23397

Microsoft 365 Apps 2023-03-14 CVSS v3.1
CVSS
9.8
KEV

Description

Microsoft Outlook Elevation of Privilege Vulnerability

Summary dbcve.org

This is an elevation of privilege vulnerability in Microsoft Outlook that allows authenticated attackers to gain higher permissions than originally granted, potentially leading to unauthorized access to sensitive data or system resources.

Mitigation

Apply Microsoft security updates for Outlook immediately, as this vulnerability has known active exploitation; prioritize patching affected Outlook clients and servers.

Patch Commit

Weakness (CWE)

CWE-20 Improper Input Validation
CWE-294

EPSS Score

97.41%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE