CVE-2023-35311 is a high-severity security feature bypass vulnerability affecting Microsoft Outlook, Microsoft 365 Apps, and Microsoft Office products. With a CVSS score of 8.8, it allows an unauthenticated attacker to achieve high impact on confidentiality, integrity, and availability with low attack complexity, though user interaction is required. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog. Despite active exploitation, no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is currently available, though it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2013:-:-:*:-:-:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:2013:sp1:*:*:rt:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.