Microsoft’s Outlook for Windows flaw CVE-2023-23397 could expose a user’s NTLM credentials without the user opening or previewing an email. Microsoft disclosed and patched it on March 14, 2023, after finding limited, targeted abuse. CERT-EU reported attacks from April through December 2022 against a limited number of European organizations. Those reports describe historical activity; they do not establish that the campaign is active today.
How the Outlook vulnerability worked
Microsoft classified CVE-2023-23397 as a critical elevation-of-privilege vulnerability in Outlook for Windows. An attacker could send a crafted email containing an extended MAPI reminder property with a UNC path to an SMB share under the attacker’s control. When Outlook retrieved and processed the message, it could connect to that share without the recipient taking an action. Microsoft’s advisory states, “No user interaction is required.” Microsoft’s CVE-2023-23397 advisory explains the mechanism and fix.
The risk was not simply that Outlook might display malicious content. The connection could send an NTLM negotiation message to the attacker’s server, exposing credentials that could potentially be relayed to other systems that accept NTLM authentication. CERT-EU noted that exploitation could occur before an email was viewed in the Preview Pane. CERT-EU’s advisory describes the reported attack period and response measures.
What “since last April” means
Here, “last April” means April 2022, not April 2026. Microsoft disclosed the vulnerability on March 14, 2023. CERT-EU’s March 15, 2023 advisory says the reported attacks occurred between April and December 2022. It also says Microsoft Threat Intelligence attributed the targeted use to a Russia-based threat actor.
#1 Best Overall
- STREAMLINED & INTUITIVE UI, DVD FORMAT | Intelligent desktop | Personalize your experience for simpler efficiency | Powerful security built-in and enabled.
- OEM IS TO BE INSTALLED ON A NEW PC with no prior version of Windows installed and cannot be transferred to another machine.
- OEM DOES NOT PROVIDE SUPPORT | To acquire product with Microsoft support, obtain the full packaged “Retail” version.
- PRODUCT SHIPS IN PLAIN ENVELOPE | Activation key is located under scratch-off area on label.
- GENUINE WINDOWS SOFTWARE IS BRANDED BY MIRCOSOFT ONLY.
The reporting describes limited, targeted attacks against European organizations in government, military, energy, and transportation. The cited advisories do not provide a victim count. A March 27, 2023 SecurityWeek report likewise notes Microsoft’s evidence of potential exploitation as early as April 2022. This timeline should not be read as proof of current exploitation.
Which Outlook products were affected
The vulnerable component was the Outlook client for Windows, not every Outlook app or Microsoft 365 service. Microsoft said all supported Windows versions of Outlook were affected. CERT-EU specifically listed Outlook 2013, Outlook 2016, Outlook 2019, Office LTSC 2021, and Microsoft 365 Apps for Enterprise.
| Product or service | Status for CVE-2023-23397 |
|---|---|
| Outlook for Windows | Affected; Microsoft said all supported Windows versions were affected. |
| Outlook for Android and iOS | Not affected, according to Microsoft. |
| Outlook for Mac | Not affected, according to Microsoft. |
| Outlook on the web and other Microsoft 365 services | Not affected, according to Microsoft. |
Mailbox hosting does not determine whether the Windows client needs the fix. Microsoft said to install the Outlook update regardless of whether mail is hosted by Exchange Online, Exchange Server, or another provider. Exchange Server’s March 2023 security update and Exchange Online offered a separate defense-in-depth measure for new messages by dropping the relevant property during TNEF conversion; that measure did not replace updating Outlook.
Rank #2
- FIDO2 SECURITY KEY: A versatile, tamper-evident USB-A authentication device with sensitive presence detection for online security. FIDO 2.0 level 1 and U2F certified
- PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
- BROAD COMPATIBILITY: Works with Windows, Linux and USB-A devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, ensuring secure use across various platforms, including Thales, Microsoft, AWS, and Google
- ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
- THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
What administrators should do
1. Install the Outlook security update
Apply Microsoft’s security update for the Outlook for Windows release actually installed in your environment. The fix changes Outlook’s handling so the reminder-file path is used only when it points to a local, intranet, or trusted network source. The cited guidance does not establish current build numbers, so use Microsoft’s update guidance for the installed release rather than relying on an old version number.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitches2. Search for potentially affected items
Microsoft provides a script to search Exchange mailboxes for messages, tasks, and calendar items containing the relevant PidLidReminderFileParameter property. Review the results and decide whether found items need modification. CERT-EU recommends running the script in audit mode first: cleanup can destroy forensic evidence and, in severe cases, cause data loss.
3. Investigate possible credential exposure
If there is evidence of a suspicious item or attempted connection, examine the relevant account and network activity using Microsoft’s current investigation guidance. Microsoft’s investigation indicators summarized by SecurityWeek include suspicious messages, tasks, and calendar items; Exchange items with the property; NTLM activity to untrusted resources; WebDAV attempts; SMBClient logs; and suspicious outbound SMB firewall events. Preserve relevant evidence before making changes that could remove it.
Rank #3
- PHISHING-RESISTANT 2FA: Cryptographically binds to real domains, making phishing attacks impossible unlike SMS codes or authenticator apps.
- 3-SIDE CAPACITIVE TOUCH: Tap the end, left, or right side to authenticate, so it works in any orientation or crowded USB port.
- MULTI-COLOR LED INDICATOR: Blue means ready, blinking blue means tap now, green means success, and red means error for instant status feedback.
- IP68 WATERPROOF & BATTERY-FREE: Crush-resistant one-piece construction survives daily carry on a keychain or in a bag for years without any batteries.
- UNIVERSAL COMPATIBILITY: Works with Google, Microsoft, Apple, GitHub, AWS, and any FIDO2 / U2F / WebAuthn service, storing up to 100 passkeys.
4. Reduce exposure to remote SMB connections
CERT-EU recommends blocking outbound TCP 445/SMB at perimeter, local firewall, and VPN layers to reduce authentication exposure to remote shares. Organizations can also consider placing high-value accounts in the Protected Users security group. That choice needs compatibility review because some applications require NTLM.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why patching remains the primary response
Network restrictions and investigation can reduce risk or help identify suspicious activity, but they complement rather than replace Microsoft’s Outlook update. Microsoft recommended installing the update regardless of mail-hosting arrangement or whether an organization supports NTLM. The 2023 campaign reports establish the vulnerability’s historical use and affected platform; they do not establish a present-day campaign status.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

