Microsoft's CVE-2023-23397 is an Outlook for Windows elevation-of-privilege flaw that can be exploited to coerce a victim's system into leaking NTLM credentials, prompting defenders to prioritize Microsoft's security update and related mitigations. SecurityScorecard reported that the vulnerability affects all supported Outlook for Windows versions and highlighted the risk of credential theft through malicious messages that trigger outbound authentication without user interaction.
SecurityScorecard said it observed 2,581 data transfers between January 15 and March 15 involving two IP addresses believed to be tied to a Ukrainian local government entity and a Ukrainian bank, including suspicious SMB traffic over TCP 445 and multiple large transfers that could indicate exfiltration. Several external IPs contacting the possible targets had VirusTotal detections or had appeared in earlier ransomware and data-theft investigations, although the report noted prior public research linked exploitation of CVE-2023-23397 to a nation-state espionage actor and warned that any infrastructure overlap does not necessarily mean the same operators were involved.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
SecurityScorecard published research describing suspicious SMB traffic and large data transfers involving two IP addresses linked to a Ukrainian local government entity and a Ukrainian bank in the context of CVE-2023-23397. The report noted overlaps with infrastructure previously tied to ransomware and data-theft investigations, while cautioning that available research had linked exploitation of the flaw to a nation-state espionage actor rather than financially motivated groups.
SecurityScorecard's traffic sample concluded on March 15 after capturing 2,581 data transfers involving the two possible target IP addresses. The researchers also identified 268 transfers of 1 MB or more involving 56 unique IP addresses for closer review as possible exfiltration activity.
A third external IP address was observed contacting TCP port 445 of one possible target IP address on February 26. This added to the set of suspicious SMB connections identified during the monitoring period.
One of the possibly malicious IP addresses that contacted the first target also communicated with the second possible target IP address on February 25. SecurityScorecard highlighted this as part of the suspicious traffic pattern around possible CVE-2023-23397 exploitation.
A second suspicious contact to TCP port 445 of one possible target IP address was observed on February 22. Two of the three IPs seen making such contacts had vendor detections in VirusTotal.
One of three external IP addresses observed contacting TCP port 445 of a possible target IP address did so on January 31 during SecurityScorecard's monitoring period. Researchers flagged port 445 traffic because Microsoft had advised defenders to watch for SMB-related exploitation activity.
SecurityScorecard researchers began a traffic collection period focused on two IP addresses associated with a Ukrainian local government entity and a Ukrainian bank after assessing they may have been likely targets of activity exploiting CVE-2023-23397.
Microsoft published security guidance for CVE-2023-23397, an elevation-of-privilege vulnerability affecting Outlook for Windows. The guidance noted that an update was available and recommended mitigations including avoiding NTLM and blocking outbound SMB traffic on TCP port 445.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
securityscorecard.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.