What happened
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
Affected versions
Office: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
PoC-in-GitHub · sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAYExploit for the CVE-2023-23397★ 158sqrtZeroKnowledge2023-03-15CandidatePoC-in-GitHub · j0eyv/CVE-2023-23397★ 1j0eyv2023-03-16CandidatePoC-in-GitHub · alicangnll/CVE-2023-23397CVE-2023-23397 - Microsoft Outlook Vulnerability★ 3alicangnll2023-03-16CandidatePoC-in-GitHub · grn-bogo/CVE-2023-23397Python script to create a message with the vulenrability properties set★ 4grn-bogo2023-03-16CandidatePoC-in-GitHub · ka7ana/CVE-2023-23397Simple PoC in PowerShell for CVE-2023-23397★ 40ka7ana2023-03-16CandidatePoC-in-GitHub · api0cradle/CVE-2023-23397-POC-Powershell★ 345api0cradle2023-03-16CandidatePoC-in-GitHub · im007/CVE-2023-23397CVE-2023-23397 Remediation Script (Powershell)★ 0im0072023-03-17CandidatePoC-in-GitHub · ahmedkhlief/CVE-2023-23397-POCExploit POC for CVE-2023-23397★ 6ahmedkhlief2023-03-17CandidatePoC-in-GitHub · BillSkiCO/CVE-2023-23397_EXPLOITGenerates meeting requests taking advantage of CVE-2023-23397. This requires the outlook thick client to send.★ 7BillSkiCO2023-03-17CandidatePoC-in-GitHub · djackreuter/CVE-2023-23397-PoC★ 9djackreuter2023-03-18CandidatePoC-in-GitHub · moneertv/CVE-2023-23397CVE-2023-23397 C# PoC★ 1moneertv2023-03-18CandidatePoC-in-GitHub · ahmedkhlief/CVE-2023-23397-POC-Using-Interop-Outlook★ 2ahmedkhlief2023-03-19CandidatePoC-in-GitHub · Trackflaw/CVE-2023-23397Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.★ 132Trackflaw2023-03-20CandidatePoC-in-GitHub · SecCTechs/CVE-2023-23397Patch for MS Outlook Critical Vulnerability - CVSS 9.8★ 1SecCTechs2023-03-20CandidatePoC-in-GitHub · tiepologian/CVE-2023-23397Proof of Concept for CVE-2023-23397 in Python★ 25tiepologian2023-03-21CandidatePoC-in-GitHub · BronzeBee/cve-2023-23397Python script for sending e-mails with CVE-2023-23397 payload using SMTP★ 14BronzeBee2023-03-22CandidatePoC-in-GitHub · Cyb3rMaddy/CVE-2023-23397-ReportAn exploitation demo of Outlook Elevation of Privilege Vulnerability★ 1Cyb3rMaddy2023-03-24CandidatePoC-in-GitHub · Zeppperoni/CVE-2023-23397-PatchCVE-2023-23397 powershell patch script for Windows 10 and 11★ 0Zeppperoni2023-03-24CandidatePoC-in-GitHub · jacquesquail/CVE-2023-23397★ 0jacquesquail2023-03-29CandidatePoC-in-GitHub · P4x1s/CVE-2023-23397-POCCVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。★ 3P4x1s2023-03-31CandidatePoC-in-GitHub · vlad-a-man/CVE-2023-23397CVE-2023-23397 PoC★ 8vlad-a-man2023-05-07CandidatePoC-in-GitHub · Muhammad-Ali007/OutlookNTLM_CVE-2023-23397★ 22Muhammad-Ali0072023-07-14CandidatePoC-in-GitHub · Pushkarup/CVE-2023-23397This script exploits CVE-2023-23397, a Zero-Day vulnerability in Microsoft Outlook, allowing the generation of malicious emails for testing and educational purposes.★ 4Pushkarup2023-10-26CandidatePoC-in-GitHub · TheUnknownSoul/CVE-2023-23397-PoWProof of Work of CVE-2023-23397 for vulnerable Microsoft Outlook client application.★ 1TheUnknownSoul2024-03-20CandidatePoC-in-GitHub · Symbolexe/CVE-2023-23397CVE-2023-23397: Remote Code Execution Vulnerability in Microsoft Outlook★ 0Symbolexe2024-06-22CandidatePoC-in-GitHub · Gilospy/CVE-2023-23397Demonstration of CVE-2023-23397 Outlook Privellege Escalation vulnerability★ 0Gilospy2025-04-07CandidatePoC-in-GitHub · Phaedrik/CVE-2023-23397-POCTwo POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.★ 1Phaedrik2026-01-09CandidatePoC-in-GitHub · praneethnaidu1910-cmd/cve-2023-23397-purple-team★ 0praneethnaidu1910-cmd2026-08-26CandidatePoC-in-GitHub · ZHOUCC-CPU/cve-2023-23397-detection-labDetection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.★ 0ZHOUCC-CPU2026-08-28CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.