Attackers exploited CVE-2023-23397, a Microsoft Outlook elevation-of-privilege flaw, by sending specially crafted messages that triggered Outlook to authenticate automatically to attacker-controlled servers without user interaction. The vulnerability exposed NTLM credential hashes and was used in the wild against government, military, energy, and transportation organizations in Europe, with Microsoft attributing observed activity to a Russia-based threat actor. Research also showed that real attacks used Outlook task messages in addition to the appointment-based technique highlighted in early proof-of-concept reporting.
Microsoft released a patch and published remediation guidance for Exchange administrators, including a PowerShell tool to identify and clean up malicious items tied to the vulnerable property. The CVE-2023-23397.ps1 script supports audit and cleanup modes across Exchange Server and Exchange Online, producing CSV results and allowing administrators to clear the property or delete flagged items. Operational guidance covers required roles, impersonation and authentication setup, and troubleshooting for large mailbox environments, underscoring the need to patch Outlook clients and retroactively hunt for malicious messages in mailboxes.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Microsoft issued a patch for the Outlook elevation-of-privilege vulnerability CVE-2023-23397 after CERT-UA reported the issue. The flaw allowed specially crafted emails to coerce NTLM authentication to attacker-controlled servers.
MDSec previously demonstrated a proof of concept for exploiting CVE-2023-23397 using an Outlook appointment message. This established public technical details for the attack path before broader reporting on in-the-wild abuse.
Microsoft Threat Intelligence assessed that a Russia-based threat actor exploited CVE-2023-23397 against government, military, energy, and transportation organizations in Europe. The observed activity occurred between April 2022 and December 2022.
Unit 42 reported that Iranian-linked xHunt activity in 2020 used Outlook reminder UNC paths to harvest NTLM credentials, a technique later noted as relevant to CVE-2023-23397-style abuse.
Deep Instinct Threat Lab reported finding additional malicious samples exploiting CVE-2023-23397 and grouped them into five clusters. It also observed that real-world attacks used Outlook task messages rather than only appointment messages shown in prior proof-of-concept work.
Microsoft made available a PowerShell script to help administrators retroactively search Exchange environments for potentially malicious Outlook messages exploiting CVE-2023-23397. The script supports auditing and cleanup of mail, calendar, and task items.
Deep Instinct said it found extracts from malicious emails sent to Polish targets that were dated to September and were not returned by the cited VirusTotal query. The finding added evidence of in-the-wild exploitation artifacts.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
microsoft.github.io
Open sourcedeepinstinct.com
Open sourceunit42.paloaltonetworks.com
Open sourcemdsec.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.