CVE-2023-35311
published 2023-07-11CVE-2023-35311: Microsoft Outlook Security Feature Bypass Vulnerability
PriorityP180high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-08-01
Exploited in the wild
EPSS
15.52%
96.4th percentile
Microsoft Outlook Security Feature Bypass Vulnerability
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_2019 | >= 19.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_outlook_2013 | >= 14.0.0 < 15.0.5571.1000 | 15.0.5571.1000 |
| microsoft | microsoft_outlook_2013_service_pack_1 | >= 15.0.0.0 < 15.0.5571.1000 | 15.0.5571.1000 |
| microsoft | microsoft_outlook_2016 | >= 16.0.0.0 < 16.0.5404.1000 | 16.0.5404.1000 |
| microsoft | office | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | outlook | — | — |
| microsoft | outlook | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_outlook_2013 | — | — |
| msrc | microsoft_outlook_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_outlook_2016 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
registryHKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION↗
- →Detect child processes spawned by Microsoft Office applications on Windows, which may indicate exploitation of CVE-2023-35311 or related chained vulnerabilities ↗
- →CVE-2023-35311 exploitation requires the victim to click a specially crafted URL in Outlook; the Preview Pane is also an attack vector. Monitor for Outlook opening UNC, SMB, or file:// type URLs as a suspicious indicator ↗
- →The attacker bypasses the Microsoft Outlook Security Notice prompt; alert on Outlook processes that navigate to external URLs without triggering the standard security warning dialog ↗
- →Storm-0978/RomCom is likely to chain CVE-2023-35311 with CVE-2023-32049 (SmartScreen bypass) and CVE-2023-36884 (Office/Windows HTML RCE); correlate detections across these three CVEs for the same host/user ↗
- ·The four C2 IP addresses (74.50.94.156, 104.234.239.26, 94.232.40.34, 66.23.226.102) and the five SHA-256 hashes are attributed to the broader Storm-0978/RomCom campaign (CVE-2023-36884 chain); they are associated with the campaign context in which CVE-2023-35311 is chained, not exclusively tied to CVE-2023-35311 alone ↗
- ·After installing the July 2023 Outlook security updates, access to UNC, SMB, and file:// type URLs is restricted to Local, Intranet, or Trusted Sites zones; legitimate internal links may break unless added to the Trusted Site Zone ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa7.5HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3w2f-j9r3-9h89: Microsoft Outlook Security Feature Bypass Vulnerability
ghsa_unreviewed·2023-07-11
CVE-2023-35311 [HIGH] CWE-367 GHSA-3w2f-j9r3-9h89: Microsoft Outlook Security Feature Bypass Vulnerability
Microsoft Outlook Security Feature Bypass Vulnerability
VulnCheck
Microsoft Outlook Security Feature Bypass Vulnerability
vulncheck·2023·CVSS 8.8
CVE-2023-35311 [HIGH] CWE-367 Microsoft Outlook Security Feature Bypass Vulnerability
Microsoft Outlook Security Feature Bypass Vulnerability
Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.
Affected: Microsoft Outlook
Required Action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2023-Jul; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35311; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2023-08-01
Microsoft
Microsoft Outlook Security Feature Bypass Vulnerability
vendor_msrc·2023-07-11·CVSS 8.8
CVE-2023-35311 [HIGH] CWE-367 Microsoft Outlook Security Feature Bypass Vulnerability
Microsoft Outlook Security Feature Bypass Vulnerability
FAQ: Is the Preview Pane an attack vector for this vulnerability?
Yes. The Preview Pane is an attack vector, but additional user interaction is required.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
The attacker would be able to bypass the Microsoft Outlook Security Notice prompt.
FAQ: After I installed the July 2023 security updates for Outlook, I can no longer access UNC, SMB, or file:// type URLs from my Outlook. How do I prevent this from happening?
The July 2023 Outloo
CISA
Microsoft Outlook Security Feature Bypass Vulnerability
cisa·2023-07-11·CVSS 7.5
CVE-2023-35311 [HIGH] CWE-367 Microsoft Outlook Security Feature Bypass Vulnerability
Vulnerability: Microsoft Outlook Security Feature Bypass Vulnerability
Affected: Microsoft Outlook
Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.
Required Action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-35311; https://nvd.nist.gov/vuln/detail/CVE-2023-35311
Remediation Due Date: 2023-08-01
No detection rules found.
No public exploits indexed.
Qualys
Evaluate Your Windows Endpoints for Storm-0978 Activity With Qualys Endpoint Security
blogs_qualys·2023-07-14·CVSS 7.8
CVE-2023-32046 [HIGH] Evaluate Your Windows Endpoints for Storm-0978 Activity With Qualys Endpoint Security
## Table of Contents
Summary:
Remediation:
Vulnerability Analysis:
Exploit Detection using Qualys EDR:
VMDR:
Related IOCs:
## Summary:
On July 11, Microsoft released security bulletins to fix 132 vulnerabilities. With the July Patch Tuesday, Microsoft also remediated six zero-day vulnerabilities . For your quick reference, the following are the zero-day vulnerabilities:
CVE-2023-32046 – Windows MSHTML Platform Elevation of Privilege Vulnerability
CVE-2023-32049 – Windows SmartScreen Security Feature Bypass Vulnerability
CVE-2023-36874 – Windows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2023-36884 – Office and Windows HTML Remote Code Execution Vulnerability
CVE-2023-35311 – Microsoft Outlook Security Feature Bypass Vulnerability
ADV230001 – Guidance on
Qualys
Evaluate Your Windows Endpoints for Storm-0978 Activity With Qualys Endpoint Security | Qualys
blogs_qualys·2023-07-14·CVSS 7.8
CVE-2023-32046 [HIGH] Evaluate Your Windows Endpoints for Storm-0978 Activity With Qualys Endpoint Security | Qualys
#### Table of Contents
- Summary:
- Remediation:
- Vulnerability Analysis:
- Exploit Detection using Qualys EDR:
- VMDR:
- Related IOCs:
## Summary:
On July 11, Microsoft released security bulletins to fix 132 vulnerabilities. With the July Patch Tuesday, Microsoft also remediated six zero-day vulnerabilities. For your quick reference, the following are the zero-day vulnerabilities:
1. CVE-2023-32046 – Windows MSHTML Platform Elevation of Privilege Vulnerability
2. CVE-2023-32049 – Windows SmartScreen Security Feature Bypass Vulnerability
3. CVE-2023-36874 – Windows Error Reporting Service Elevation of Privilege Vulnerability
4. CVE-2023-36884 – Office and Windows HTML Remote Code Execution Vulnerability
5. CVE-2023-35311 – Microsoft Outlook Security Feature Bypass Vulnerability
6. ADV
Krebs
Apple & Microsoft Patch Tuesday, July 2023 Edition
blogs_krebs·2023-07-12·CVSS 7.8
[HIGH] Apple & Microsoft Patch Tuesday, July 2023 Edition
Microsoft Corp. today released software updates to quash 130 security bugs in its Windows operating systems and related software, including at least five flaws that are already seeing active exploitation. Meanwhile, Apple customers have their own zero-day woes again this month: On Monday, Apple issued (and then quickly pulled) an emergency update to fix a zero-day vulnerability that is being exploited on MacOS and iOS devices.
On July 10, Apple pushed a “Rapid Security Response” update to fix a code execution flaw in the Webkit browser component built into iOS, iPadOS, and macOS Ventura. Almost as soon as the patch went out, Apple pulled the software because it was reportedly causing problems loading certain websites. MacRumors says Apple will likely re-release the patches when the glitch
Talos
Microsoft discloses more than 130 vulnerabilities as part of July’s Patch Tuesday, four exploited in the wild
blogs_talos·2023-07-11·CVSS 7.8
[HIGH] Microsoft discloses more than 130 vulnerabilities as part of July’s Patch Tuesday, four exploited in the wild
Microsoft released its monthly security update Tuesday, disclosing the most vulnerabilities as part of Patch Tuesday in more than a year.
The company released details of more than 130 vulnerabilities, the most in a month since April 2022, 10 of which are considered to be critical. The remaining vulnerabilities are “important.”
Microsoft also included an advisory in today’s Patch Tuesday that provides guidance to mitigate Microsoft-signed drivers that attackers are using maliciously in the wild. Talos recently discovered an attack that focuses on drivers certified by Microsoft’s Windows Hardware Developer Program (MWHDP) being used maliciously in post-exploitation activity. Microsoft had been previously notified of this type of activity in February 2023, and Talos researchers recently rep
Krebs
Apple & Microsoft Patch Tuesday, July 2023 Edition
blogs_krebs·2023-07-11·CVSS 7.8
[HIGH] Apple & Microsoft Patch Tuesday, July 2023 Edition
Microsoft Corp. today released software updates to quash 130 security bugs in its Windows operating systems and related software, including at least five flaws that are already seeing active exploitation. Meanwhile, Apple customers have their own zero-day woes again this month: On Monday, Apple issued (and then quickly pulled) an emergency update to fix a zero-day vulnerability that is being exploited on MacOS and iOS devices.
On July 10, Apple pushed a “Rapid Security Response” update to fix a code execution flaw in the Webkit browser component built into iOS, iPadOS, and macOS Ventura. Almost as soon as the patch went out, Apple pulled the software because it was reportedly causing problems loading certain websites. MacRumors says Apple will likely re-release the patches when the glitch
Qualys
Microsoft and Adobe Patch Tuesday, July 2023 Security Update Review
blogs_qualys·2023-07-11·CVSS 7.8
[HIGH] Microsoft and Adobe Patch Tuesday, July 2023 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for July 2023
Adobe Patches for July 2023
Zero-day Vulnerabilities Patched in July Patch Tuesday Edition
Other Critical Severity Vulnerabilities Patched in July Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
EXECUTE Mitigation Using Qualys Custom Assessment and Remediation (CAR)
Qualys Monthly Webinar Series
Microsoft has released July’s edition of Patch Tuesday! This installment of security updates addressed 132 security vulnerabilities in various products, features, and roles.
## Microsoft
Tenable
Microsoft’s July 2023 Patch Tuesday Addresses 130 CVEs (CVE-2023-36884)
blogs_tenable·2023-07-11·CVSS 7.5
[HIGH] Microsoft’s July 2023 Patch Tuesday Addresses 130 CVEs (CVE-2023-36884)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Microsoft and Adobe Patch Tuesday, July 2023 Security Update Review | Qualys
blogs_qualys·2023-07-11·CVSS 7.8
[HIGH] Microsoft and Adobe Patch Tuesday, July 2023 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for July 2023
- Adobe Patches for July 2023
- Zero-day Vulnerabilities Patched in July Patch Tuesday Edition
- Other Critical Severity Vulnerabilities Patched in July Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- EXECUTE Mitigation Using Qualys Custom Assessment and Remediation (CAR)
- Qualys Monthly Webinar Series
Microsoft has released July’s edition of Patch Tuesday! This installment of security updates addressed 132 security vulnerabilities in various products, features, and roles.
Talos
Microsoft discloses more than 130 vulnerabilities as part of July’s Patch Tuesday, four exploited in the wild
blogs_talos·2023-07-11·CVSS 7.8
[HIGH] Microsoft discloses more than 130 vulnerabilities as part of July’s Patch Tuesday, four exploited in the wild
## Microsoft discloses more than 130 vulnerabilities as part of July’s Patch Tuesday, four exploited in the wild
Microsoft released its monthly security update Tuesday, disclosing the most vulnerabilities as part of Patch Tuesday in more than a year.
The company released details of more than 130 vulnerabilities, the most in a month since April 2022, 10 of which are considered to be critical. The remaining vulnerabilities are “important.”
Microsoft also included an advisory in today’s Patch Tuesday that provides guidance to mitigate Microsoft-signed drivers that attackers are using maliciously in the wild. Talos recently discovered an attack that focuses on drivers certified by Microsoft’s Windows Hardware Developer Program (MWHDP) being used maliciously in post-exploitation activity. Mi
Crowdstrike
July 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July 2023 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Zscaler
Zscaler found Windows Security Vulnerabilities | 07-11-2023
blogs_zscaler·CVSS 8.8
[HIGH] Zscaler found Windows Security Vulnerabilities | 07-11-2023
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2023-07-11
Published
2023-07-11
Added to CISA KEV
Exploited in the wild