Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Microsoft addressed a bypass of its Outlook security fix with a Windows security update on May 9, 2023. The bypass, CVE-2023-29324, affected the mitigation for CVE-2023-23397, a serious Outlook for Windows flaw that could expose NTLM authentication material when a specially crafted email arrived—even if the recipient did not open or interact with it. These are historical 2023 vulnerabilities, not a new October 2026 patch announcement.
What were CVE-2023-23397 and CVE-2023-29324?
The two CVEs describe related but different problems. Microsoft’s original March 2023 advisory covered CVE-2023-23397, an Outlook for Windows vulnerability. CVE-2023-29324 was a later-reported bypass of a security check used in the defense against that original flaw.
| Vulnerability | Affected component and role | Timeline and remediation |
|---|---|---|
| CVE-2023-23397 | Outlook for Windows; a crafted message could trigger a remote connection and expose NTLM negotiation material. | Microsoft disclosed and addressed the original issue in March 2023 with an Outlook mitigation and related guidance. |
| CVE-2023-29324 | Windows MSHTML security-feature handling; the issue bypassed a security-zone check used by the original mitigation. | Microsoft said a Windows security update released May 9, 2023 addressed the reported bypass. |
Microsoft’s MSRC advisory, which began March 14 and was updated May 9, describes the original flaw and the later bypass: Microsoft Security Response Center: CVE-2023-23397. CSO published its analysis of the bypass on May 10, 2023: CSO’s account of Microsoft’s fix.
Could the Outlook flaw be triggered just by receiving an email?
According to Microsoft, CVE-2023-23397 required no user interaction. A specially crafted email could set the extended MAPI property PidLidReminderFileParameter to a UNC path pointing to an attacker-controlled SMB server. Outlook could then attempt a remote connection, potentially exposing NTLM negotiation material. In practical terms, opening an attachment or clicking a link was not required for the described trigger.
#1 Best Overall
- Fit: Saturn Outlook 2007-2010
- Made by Ri-Key Security - High Quality security products
- Include Transponder Chip - ID 46.
- Easy self programming Just ask us.
- Other Part Number: CIRCLE+, 692931 TP12GM37P GMX380CP B111-PT
How did the bypass work?
Microsoft’s March mitigation changed how Outlook handled the reminder sound path, restricting it to paths judged local, intranet, or trusted. CSO’s contemporaneous account of Akamai researcher Ben Barnea’s analysis described CVE-2023-29324 as a mismatch in Windows MSHTML security-zone handling: a path could be classified as local by the MapUrlToZone check while a later file operation treated it as a remote SMB path. That difference undermined the protection used against the original issue. This high-level description explains the relationship between the CVEs without providing instructions for exploiting them.
Which Outlook versions and platforms were affected?
Microsoft said supported Outlook for Windows versions were affected by CVE-2023-23397. Its advisory said Outlook for Android, iOS, and Mac, Outlook on the web, and other Microsoft 365 services were not affected by this Outlook client flaw. The advisory does not establish a complete current inventory of every product build; organizations should consult Microsoft’s current guidance for the software and versions they actually deploy.
Rank #2
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Does Outlook need to be patched if email is hosted by Exchange Online?
Yes. Microsoft recommended updating Outlook for Windows regardless of whether mail is hosted by Exchange Online, Exchange Server, or another platform. The client update and server-side defenses address different layers, so Exchange hosting does not replace the need to keep Outlook for Windows current.
Microsoft also described its March 2023 Exchange Server security update as defense in depth: Exchange Server and Exchange Online drop the relevant message property during TNEF conversion for new messages. Microsoft said Exchange Online users were already protected by that server-side measure. That is a separate control from updating the Outlook client, and it should not be treated as a substitute for the client update.
Recommended Free Tools
Rank #3
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
What did Microsoft report about exploitation and severity?
Microsoft reported limited, targeted abuse of CVE-2023-23397. Its threat-intelligence assessment attributed attacks against a limited number of European government, transportation, energy, and military organizations to a Russia-based threat actor. This is Microsoft’s stated assessment, not an independent attribution established by the CSO report. Microsoft also pointed organizations to investigation guidance for checking whether malicious messages were present.
CSO reported Microsoft’s severity rating for CVE-2023-29324 as 6.5 out of 10 (medium), while reporting CVE-2023-23397 at 9.8 out of 10. Akamai researchers argued that the bypass warranted greater concern because it could restore consequences associated with the original flaw. The figures refer to separate CVEs and should not be combined into one score.
Rank #4
- FITMENT- Replacement car key fob compatible with Chevrolet Suburban Tahoe 2007-2014/ Traverse 2009-2015/Buick Enclave 2008-2015/ Cadillac Escalade EXT ESV 2007-2014/ SRX 2007-2008/ GMC Yukon Yukon XL 2007-2013/ Acadia 2007-2015/Saturn Outlook 2007-2010
- REPLACEMENT- Key replacement parts number for OEM OUC60270 OUC60221 15913415 25839476. Please confirm vehicle made and year before purchase
- PROGRAMMING- The key is self-programmable for vehicles made before 2010( including 2010). Vehicles made AFTER 2010 are NOT on board programmable and requires professional locksmiths or dealers
- NOTE- Please make sure your vehicle is equipped with original factory trunk and remote start for the key to work. The key remote could not add features that were not included originally
- WARRANTY- Package contains 1 complete key fobs with battery and electronics installed. If any problems occur during use, please feel free to email us
What should administrators do?
- Update Outlook for Windows. Apply the appropriate current Outlook updates for deployed versions, following Microsoft’s guidance. Microsoft’s recommendation applies irrespective of the organization’s mail-hosting platform.
- Keep Windows security updates current. Microsoft said its May 9, 2023 Windows security update addressed the reported bypass. For current systems, use Microsoft’s update guidance to determine applicable updates rather than assuming the historical release alone establishes present patch status.
- Review Exchange protections separately. Confirm the relevant Exchange Server security updates and server-side protections are in place where applicable. These defenses complement, but do not replace, the Outlook client update.
- Investigate possible exposure. If the organization may have received malicious messages, follow Microsoft’s investigation guidance linked from its advisory to look for them and assess potential impact.
Microsoft’s published guidance put the client action plainly: “We strongly recommend all customers update Microsoft Outlook for Windows to remain secure.”
Quick Recap
Best Value
- Ultra-Compact FIDO2 Security Key – Plug-and-stay or carry on a keychain. This USB-C hardware security key offers portable, always-on protection for desktop and mobile use.(Item Size: 0.73 X 0.60 X 0.30 inches)
- USB-C Hardware Key for All Devices – Works with USB-C ports on PC, Mac, Android, and USB-C iPhones. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key – Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey – Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication – Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →

