CVE-2022-23280 is a security feature bypass vulnerability affecting Microsoft Outlook for Mac 2016. This medium-severity vulnerability, with a CVSS score of 5.3, allows an unauthenticated attacker to achieve low-impact confidentiality compromise over a network with low attack complexity. There is no evidence of active exploitation, nor is public exploit code available, as indicated by its absence from KEV, Metasploit, Nuclei, and ExploitDB. Despite this, the vulnerability has garnered some community attention and media coverage, appearing in two articles and two community discussions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.57CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook_2016:*:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.