Description
This detection identifies exploitation attempts targeting CVE-2023-23397, which has a CRITICAL severity rating. Microsoft's advisory names this issue the Microsoft Outlook Elevation of Privilege Vulnerability, which lets a cyberattacker trigger outbound connections that leak NTLM credential hashes to cyberattacker controlled servers, often without any user interaction.
Stats
- First seen
- March 2023
- Last seen
- October 2026
CVEs
Alert name variants
| Alert Name |
|---|
| Document-Office.Exploit.CVE-2023-23397 |
| Email-MIME.Exploit.CVE-2023-23397 |
| Email-MSG.Exploit.CVE-2023-23397 |
| Email.Exploit.CVE-2023-23397 |
| Exploit.CVE-2023-23397.1.Gen |
| Exploit.CVE-2023-23397.2.Gen |
| Exploit.CVE-2023-23397.3.Gen |
| Exploit.CVE-2023-23397.A |
| Win32.Exploit.CVE-2023-23397 |

