logo

Everything We Know About CVE-2023-23397

ID: 0fdda181-d47f-501a-81e7-997beb536bdc

STIX ID: report--0fdda181-d47f-501a-81e7-997beb536bdc

Feed Name: Huntress Blog

Threat Score
85/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress documents active exploitation of CVE-2023-23397, a critical Outlook vulnerability that allows zero-interaction theft of Net-NTLMv2 hashes via crafted calendar invites using specific MAPI properties; attackers can force Outlook to reach out to remote UNC/WebDAV resources (triggering NTLM authentication) enabling credential capture and lateral movement—Huntress provides detection artifacts (svchost.exe → rundll32.exe invoking davclnt.dll with a remote UNC/.WAV), mitigation guidance (apply Microsoft's patches immediately, disable reminders as a temporary mitigation, consider blocking outbound SMB or using Protected Users), and hunting resources from Microsoft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.