logo

Cybersecurity in the news: Understanding Microsoft Outlook vulnerability, CVE-2023-23397, mitigation strategies

ID: fc2c81d9-98ee-5ab4-a2b5-36c456757382

STIX ID: report--fc2c81d9-98ee-5ab4-a2b5-36c456757382

Feed Name: ThreatLocker Blog

Threat Score
75/100

Date Published: 2025-01-08

Date Updated: 2026-05-01

...
...

CVE-2023-23397 is a critical Outlook-for-Windows vulnerability where a specially crafted calendar invite embeds a UNC path in the reminder sound parameter, causing Outlook to automatically connect to an attacker-controlled SMB server and exposing the user's NTLM hash and username; mitigations include applying Microsoft patches, blocking outbound SMB (port 445), using Protected Users group, and employing endpoint controls such as ThreatLocker ringfencing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.