logo

Critical Outlook Vulnerability: In-Depth Technical…

ID: 43f3ce2b-a7f9-5738-b256-7c781a114055

STIX ID: report--43f3ce2b-a7f9-5738-b256-7c781a114055

Feed Name: TrustedSec blog

Threat Score
90/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

**Executive Summary:** CVE-2023-23397 is a critical Outlook vulnerability actively exploited in the wild—reportedly by a Russian military-linked group—that enables theft of NTLM credentials via specially crafted calendar/meeting invites that trigger an automatic SMB/WebDAV authentication to attacker-controlled shares; the report includes PoC PowerShell, detection (Sigma) guidance, and mitigation recommendations including blocking outbound SMB (445) and applying Microsoft patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.