cbcvebase.
CVE-2023-23397
published 2023-03-14

CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-04-04
Exploited in the wild
Microsoft Outlook Elevation of Privilege Vulnerability

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_365_apps_for_enterprise>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_2019>= 19.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_2021>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_outlook_2013_service_pack_1>= 15.0.0.0 < 15.0.5537.100015.0.5537.1000
microsoftmicrosoft_outlook_2016>= 16.0.0.0 < 16.0.5387.100016.0.5387.1000
microsoftoffice
microsoftoffice_long_term_servicing_channel
microsoftoutlook
microsoftoutlook
msrcmicrosoft_365_apps_for_enterprise_for_32-bit_systems
msrcmicrosoft_365_apps_for_enterprise_for_64-bit_systems
msrcmicrosoft_exchange_server_2016_cumulative_update_23
msrcmicrosoft_exchange_server_2019_cumulative_update_13
msrcmicrosoft_exchange_server_2019_cumulative_update_14
msrcmicrosoft_office_2019_for_32-bit_editions
msrcmicrosoft_office_2019_for_64-bit_editions
msrcmicrosoft_office_ltsc_2021_for_32-bit_editions
msrcmicrosoft_office_ltsc_2021_for_64-bit_editions
msrcmicrosoft_outlook_2013_rt_service_pack_1
msrcmicrosoft_outlook_2013_service_pack_1
msrcmicrosoft_outlook_2016
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_20h2

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL