Web: https://msrc.microsoft.com/blog/2023/03/microsoft-mitigates-outlook-elevation-of-privilege-vulnerability/

March 14, 2023, 1 p.m. |

Microsoft Security Response Center msrc-blog.microsoft.com

Summary Summary Microsoft Threat Intelligence discovered limited, targeted abuse of a vulnerability in Microsoft Outlook for Windows that allows for new technology LAN manager (NTLM) credential theft. Microsoft has released CVE-2023-23397 to address the critical elevation of privilege (EoP) vulnerability affecting Microsoft Outlook for Windows. We strongly recommend all customers update Microsoft Outlook for Windows to remain secure.

microsoft outlook privilege vulnerability

Associate Security Architect

@ Fivesky | Alpharetta, GA

Director Information Security

@ Aptos | United States - Atlanta, Georgia

DevSecOps Engineer (Belgrade - hybrid remote)

@ SMG Swiss Marketplace Group | Beograd, Serbia

Security Analytics Lead

@ Dynatrace | Tallinn, Estonia

C002543 Engineer (Digital Forensics Analysis) (NS) - THU 6 Apr RELAUNCH

@ EMW, Inc. | Mons, Wallonia, Belgium

Senior Architect Cloud and Security Engineer (Threat Modeling)

@ Publicis Groupe | Los Angeles, California, United States

Senior Cloud Security Operations Engineer - AWS

@ MUFG Investor Services | London, United Kingdom

Cybersecurity Engineer (ForgeRock openAM, SAML, OpenID, OAuth)

@ Visa | Bengaluru, India

Software Engineer, Product Security

@ Block | San Francisco, CA, United States

Security Internship - Application Security Intern

@ Highspot | Vancouver, BC

Cloud Security Engineer

@ XOR Security | Washington, DC

Cyber Security Consultant Intern - ETAS

@ Bosch Group | Plymouth, MI, United States