Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

APT28, a Russian state-sponsored threat actor, exploited a flaw in Outlook for Windows—CVE-2023-23397—that could expose authentication material without the recipient opening or previewing the message. The vulnerability was patched in March 2023, but organizations should still check for signs of targeting and remove any suspicious Outlook items identified by Microsoft’s audit guidance.

What was the Russian APT Outlook exploit?

CVE-2023-23397 was a critical Outlook privilege-escalation vulnerability exploited by APT28, also known as Fancy Bear, Forest Blizzard and Fighting Ursa. SecurityWeek reported that Palo Alto Networks identified at least 30 organizations in 14 nations targeted across three campaigns. Targets included energy and transportation organizations, as well as ministries responsible for defense, internal affairs, foreign affairs and the economy. Most were in NATO countries; additional targets were in Ukraine, Jordan and the United Arab Emirates.

Microsoft said exploitation began at least as early as April 2022. Palo Alto Networks documented campaigns from March to December 2022, in March 2023, and from September to October 2023, according to SecurityWeek. Microsoft patched CVE-2023-23397 in March 2023 and fixed a related bypass, CVE-2023-29324, in May 2023.

How could it work without a click?

An attacker could send a message containing an extended MAPI property with a UNC path pointing to an attacker-controlled SMB share. Outlook for Windows could attempt to contact that server automatically, before the recipient viewed the message in the Preview Pane. Microsoft summarized the issue by saying, “No user interaction is required.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WithSecure described the property as an external custom notification-sound location. When Outlook tried to reach it, the connection could expose NTLM authentication material to the attacker-controlled server. An attacker could then capture the resulting NTLM negotiation message and attempt to relay it to another system that accepted NTLM authentication.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

This was not the same as a message simply revealing a user’s password in readable form. The risk was exposure of authentication material that could potentially be used in an NTLM relay attack, creating a route toward access to other systems, lateral movement or intelligence collection. A successful relay depended on other systems and conditions; the Outlook flaw itself did not guarantee that broader access.

Which Outlook users and services were affected?

Environment What Microsoft said Practical implication
Outlook for Windows Microsoft said this client required updating to remain secure. Apply the relevant Outlook security update and assess whether the organization was targeted.
Microsoft 365 online services Microsoft said these services did not support NTLM authentication and were not vulnerable to being attacked by these messages. This statement concerns the online services; it should not be read as saying that Outlook for Windows was safe without an update.

The distinction matters: the reported attack relied on Outlook for Windows making the connection and on NTLM authentication being available at a system the attacker could target. Publicly available information does not establish exposure details for every Outlook edition, platform or configuration, so organizations should follow Microsoft’s guidance for their own deployment rather than generalizing the cloud-service statement to all Outlook clients.

Rank #2
Sale
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should an organization check for targeting?

Microsoft provided an audit and cleanup script for CVE-2023-23397. Review its output rather than treating installation of an update as proof that no earlier targeting occurred.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Update Outlook for Windows using the applicable Microsoft security update.
  2. Run Microsoft’s CVE-2023-23397 audit and cleanup script, following Microsoft’s instructions for the organization’s environment.
  3. Review any reported tasks, email messages or calendar items that point to a share the organization does not recognize.
  4. Investigate suspicious items, then remove them or clear the parameter that points to the unrecognized share, as appropriate under Microsoft’s guidance.
  5. Escalate suspicious findings through the organization’s incident-response process and assess whether exposed authentication material could have been relayed to other systems.

Microsoft said that if the script finds no such objects, it is unlikely the organization was targeted via this vulnerability. That finding is useful evidence, not a substitute for broader incident investigation when other indicators of compromise exist.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
Sale
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What should security teams take away?

  • Patch the Windows client: Microsoft’s recommendation was to update Outlook for Windows to remain secure.
  • Check historical items as well as current software: the vulnerability had been exploited before the March 2023 patch, so audit results can matter even after updating.
  • Assess potential credential relay separately: an audit finding signals an item to investigate; it does not by itself prove a successful relay or broader compromise.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.