logo

CVE-2023-23397

ID: 16a62057-5ab7-5db3-b1b3-c183de7b2582

STIX ID: report--16a62057-5ab7-5db3-b1b3-c183de7b2582

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

An Outlook vulnerability allows an attacker to send an email containing an extended MAPI property with a UNC path that forces Outlook to automatically authenticate (NTLM) to an attacker-controlled SMB share. This can expose a user's Net-NTLMv2 hash without any user interaction, enabling NTLM relay attacks to authenticate to other services as the user.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.