See our Managed Services and learn how we can help your firm.

Microsoft Outlook Privilege Elevation Vulnerability (CVE-2023-23397)

March 16, 2023

Cornerstone.IT Gold Microsoft Partner

CISA added a zero-day vulnerability affecting Microsoft Outlook that is actively exploited in the wild. Microsoft has released a patch for the vulnerability as part of their March 2023 Patch Tuesday.

This vulnerability in Microsoft Outlook allows an unauthenticated attacker to steal credentials (via code hash) by sending specially crafted email to their victims. The vulnerability triggers automatically when the specially crafted email is retrieved and processed by the Microsoft Outlook client.

Affected Products

  • All versions of Microsoft Outlook from 2013 to the newest

Remediation

  • Install the patch provided by Microsoft.
  • If you are using Microsoft Outlook, you can check if the patch has been installed by going to File > Office Account > Update Options > View Updates. If the patch has not been installed, you can click on the Update Now button to install it.

References

Contact Cornerstone.IT for assistance remediating this issue. If you are a small or mid-sized law firm, Cornerstone.IT’s dedicated 24/7 Network Operations Center (NOC) can help you with future patches, monitoring, and other mundane tasks that keep you from focusing on moving your firm forward.