CVE-2023-23397

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 21 articles

EPSS Score

Source: FIRST.org · 2026-05-24
93.49%
probability
This CVE has a 93.49% probability of being exploited in the next 30 days.
0% Top 99.8th percentile of all CVEs 100%

CVSS v3.1

Source: NVD
9.8
CRITICAL
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

NVD
Microsoft Outlook Elevation of Privilege Vulnerability

Affected Products

microsoft
365 apps
microsoft
office
microsoft
office long term servicing channel
microsoft
outlook

Attack Intelligence

Google Project Zero

Patched
March 14, 2023
Reported by
CERT-UA, Microsoft Incident, Microsoft Threat Intelligence (MSTI)
Root Cause Analysis
???

Exploits & PoC

api0cradle/CVE-2023-23397-POC-Powershell

PoC CVE-2023-23397 — api0cradle/CVE-2023-23397-POC-Powershell

347
159
Trackflaw/CVE-2023-23397

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

127
ka7ana/CVE-2023-23397

Simple PoC in PowerShell for CVE-2023-23397

39
tiepologian/CVE-2023-23397

Proof of Concept for CVE-2023-23397 in Python

25
Muhammad-Ali007/OutlookNTLM_CVE-2023-23397

PoC CVE-2023-23397 — Muhammad-Ali007/OutlookNTLM_CVE-2023-23397

22
BronzeBee/cve-2023-23397

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

14
BillSkiCO/CVE-2023-23397_EXPLOIT

Generates meeting requests taking advantage of CVE-2023-23397. This requires the outlook thick client to send.

7
vlad-a-man/CVE-2023-23397

CVE-2023-23397 PoC

7
9 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 93.49%
CVSS v3.1 9.8
Mentions 21
Last Seen May 27, 2026

CNA Information

Analyst Note

CVE-2023-23397 is a critical Microsoft Outlook elevation of privilege vulnerability with a CVSS score of 9.8, documented by CERT-EU and researched by Google Project Zero, providing strong technical validation. The confirmed status is well-justified by the severity rating and authoritative source documentation, though inclusion in CISA KEV would provide additional confidence.

Threat Actors 26

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
APT 29
apt_group Information theft and espionage 🇷🇺 RU
Cobalt
apt_group Financial crime 🇷🇺 RU
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Harvester
apt_group Information theft and espionage Unknown
Hacking Team
apt_group 🇮🇹 IT
Stone Panda
apt_group Information theft and espionage 🇨🇳 CN
APT3
apt_group Information theft and espionage 🇨🇳 CN
Infy
apt_group Information theft and espionage 🇮🇷 IR
APT35
apt_group Information theft and espionage 🇮🇷 IR
TA428
apt_group Information theft and espionage 🇨🇳 CN
[Unnamed group]
apt_group 🇨🇳 CN
APT 22
apt_group Information theft and espionage 🇨🇳 CN
UAC-0063
apt_group 🇷🇺 RU
Rocke
apt_group 🇨🇳 CN
Pat Bear
apt_group 🇸🇾 SY
Operation Digital Eye
apt_group Information theft and espionage 🇨🇳 CN
Unnamed Actor
apt_group 🇨🇳 CN
Operation Parliament
apt_group Information theft and espionage 🇵🇰 PK
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Iron Group
apt_group Information theft and espionage 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
Lurk
apt_group Financial crime 🇷🇺 RU
Operation Black Atlas
apt_group Financial crime
Unit 29155
apt_group Sabotage and destruction 🇷🇺 RU

Triage Info

Decided atMar 03, 2026