CVE-2023-23397

CVE Published 2023-03-14
Related CWE(s) CWE-20: Improper Input Validation, CWE-294: Authentication Bypass by Capture-replay
Related Vendor(s) microsoft
Related Product(s) office, 365_apps, outlook
Exploitation Reported (CISA KEV) 2023-03-14
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Microsoft Outlook Elevation of Privilege Vulnerability

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Threat Reports Related to CVE-2023-23397

Report

Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials

This blog post by researchers at Microsoft Threat Intelligence outlines activity they observed by Forest Blizzard using a tool they named ...

Report

Ongoing ITG05 operations leverage evolving malware arsenal in global campaigns

This Security Intelligence blog post by researchers at IBM's X-Force describes activity by ITG05 - a group which shows overlap with APT28/Forest ...

Associated CAPEC Patterns

References