Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteSeveral related Outlook and Windows vulnerabilities used custom reminder sounds, but they did not all do the same thing. CVE-2023-23397 could expose a Windows user’s Net-NTLMv2 challenge-response material when an Outlook reminder fired; later Outlook mitigation bypasses reopened the sound-path issue; and CVE-2023-36710 affected Windows Media Foundation sound-file parsing and was reported as part of a zero-click remote-code-execution chain.
How could a sound file trigger a zero-click Outlook flaw?
Outlook reminders can use a custom sound. In the original CVE-2023-23397 attack, a crafted message set the extended MAPI property PidLidReminderFileParameter to a UNC path on an attacker-controlled SMB server. When Outlook for Windows was open and the reminder fired, Outlook could try to access that remote path without the recipient opening or interacting with the message.
That connection could disclose the signed-in Windows user’s Net-NTLMv2 challenge-response material. An attacker could try to relay it to another NTLM service or crack it offline; Microsoft notes that the material is not usable for a Pass-the-Hash attack. The relevant trigger was the reminder firing in Outlook, not simply receiving a message.
Which vulnerabilities were involved, and what did each do?
“Sound-file vulnerability” is not one root cause. The reported issues involved Outlook’s handling of reminder paths as well as Windows’ parsing of sound files.
#1 Best Overall
| CVE | Component or role | Reported impact |
|---|---|---|
| CVE-2023-23397 | Outlook on Windows; a crafted reminder used PidLidReminderFileParameter to point to a remote UNC path. |
Could expose Net-NTLMv2 challenge-response material when the reminder fired without user interaction. Microsoft classified it as a critical elevation-of-privilege vulnerability. |
| CVE-2023-29324 | Outlook mitigation bypass reported by Akamai; it involved Windows’ MapUrlToZone path classification. |
Bypassed an initial mitigation that checked whether a custom sound path was from an Internet zone. |
| CVE-2023-35384 | A later reported bypass of the reminder-sound mitigation. | Reopened the sound-path attack route; it was discussed with CVE-2023-36710 as part of a reported chain. |
| CVE-2023-36710 | Windows Media Foundation sound-file parsing. | Parsing a sound file was reported as a component of a zero-click remote-code-execution chain when combined with the Outlook sound-path issue. |
Akamai’s technical account describes Outlook playing reminder WAV files through Windows’ PlaySound function and discusses WAV parsing, the Audio Compression Manager, and codecs in the Windows audio stack. This describes the areas examined in that research; it does not mean that every WAV file or every media player is vulnerable.
Who was affected, and was the flaw exploited?
Microsoft said all versions of Outlook on Windows were affected by the original CVE-2023-23397 flaw. Outlook for Android, iOS, and Mac, and Outlook on the web used without the Outlook client, were not affected by that vulnerability.
Rank #2
Microsoft said it found evidence of potential exploitation dating back to April 2022. Its assessment was that a Russia-based actor used CVE-2023-23397 in targeted attacks against a limited number of European organizations in government, transportation, energy, and military sectors. That attribution and scope are Microsoft’s assessment; it is not evidence that every later bypass or the reported RCE chain was exploited in the wild.
Quick Recap
Rank #4
What should Outlook and Exchange customers do?
- Install the Outlook security update. Microsoft’s advice applies whether mail is hosted in Exchange Online, Exchange Server, or another platform. The Outlook fix restricts custom reminder sound paths to local, intranet, or trusted network sources.
- Apply Exchange protections as additional defense in depth. Microsoft’s Exchange Server March 2023 security update and Exchange Online handling drop
PidLidReminderFileParameterduring TNEF conversion for new messages. This is an additional Exchange-side protection, not a substitute for the Outlook update.
How can an organization check for suspected historical exposure?
- Search Exchange mailboxes for messages, calendar items, and tasks with
PidLidReminderFileParameterset. Review values that point to servers in the Internet zone. - Check available security telemetry for relevant activity, including endpoint, network, identity, and Exchange records. Correlating these sources can help distinguish an attempted remote connection from credential exposure.
- Account for mailbox coverage gaps. Microsoft’s scanning script does not cover every scenario. Local PST stores and messages received through other mailbox services configured in Outlook may fall outside an Exchange scan.
- Interpret WebDAV artifacts cautiously. Microsoft warns that a WebDAV process artifact alone does not prove credentials were sent or leaked; it may represent an attempted connection in which credentials were not transmitted.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

