RW
RiskWire Real-time vulnerability intelligence
This week Pricing Live dashboard
Critical 9.8 KEV-listed

CVE-2023-23397

Exploitation of Microsoft Exchange Server Vulnerability CVE-2023-23397

Vendor / product: Microsoft Outlook
Event date: 2023-01-01
Public PoC: Yes
First tracked by RiskWire: 2026-09-25

CISA KEV catalog

Added to KEV
Federal remediation due
2023-04-04 (1270 days overdue)
Ransomware campaign use
Unknown
CISA description
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
Required action
Apply updates per vendor instructions.

Named threat actors

APT28Fancy Bear

Sources & citations (8)

References

See CVE-2023-23397 in context

RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.

Book a 20-min demo →