EXPOSURES › CVE-2023-35311
CVE-2023-35311
HIGH ⌖ ON CISA KEV · EXPLOITEDAttackers can bypass Outlook's security prompts, potentially leading to malware infection and data compromise.
CVE-2023-35311 allows attackers to circumvent Outlook's security notices, enabling malicious attachments or links to execute without user awareness. DIB organizations using Outlook must immediately patch and reinforce user security training to prevent exploitation and maintain CMMC compliance. Failure to address this actively exploited vulnerability poses a significant risk of data breach and system compromise.
Shame score — A bypass of a core security feature in a widely-used product demonstrates a significant oversight in Microsoft's security design, especially given active exploitation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |