Skip to content
COOEY

EXPOSURES › CVE-2023-35311

CVE-2023-35311

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-07-11 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-35311 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Attackers can bypass Outlook's security prompts, potentially leading to malware infection and data compromise.

CVE-2023-35311 allows attackers to circumvent Outlook's security notices, enabling malicious attachments or links to execute without user awareness. DIB organizations using Outlook must immediately patch and reinforce user security training to prevent exploitation and maintain CMMC compliance. Failure to address this actively exploited vulnerability poses a significant risk of data breach and system compromise.

Shame score — A bypass of a core security feature in a widely-used product demonstrates a significant oversight in Microsoft's security design, especially given active exploitation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized