8.8

CVE-2023-35311

Warnung

Microsoft Outlook Security Feature Bypass Vulnerability

Microsoft Outlook Security Feature Bypass Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ 365 Apps Version - SwEdition enterprise
Microsoft ≫ Office 2019 Version - HwPlatform x64
Microsoft ≫ Office 2019 Version - HwPlatform x86
Microsoft ≫ Office 2021 Version - SwEdition ltsc SwPlatform - HwPlatform x64
Microsoft ≫ Office 2021 Version - SwEdition ltsc SwPlatform - HwPlatform x86
Microsoft ≫ Outlook Version 2013 Update - Edition - SwEdition - SwPlatform -
Microsoft ≫ Outlook Version 2013 Update sp1 SwEdition rt
Microsoft ≫ Outlook Version 2016

11.07.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Outlook Security Feature Bypass Vulnerability

Schwachstelle

Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.

Beschreibung

Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 15.52% 0.964
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35311
Patch
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-35311
US Government Resource