CVE-2023-35636 is a Microsoft Outlook Information Disclosure Vulnerability affecting Microsoft 365 Apps, Microsoft Office, and Microsoft Office Long Term Servicing Channel. With a CVSS score of 6.5 (Medium), this vulnerability can lead to high confidentiality impact through a network-based attack requiring user interaction. While not currently listed in CISA's KEV catalog and lacking public exploit code, its high FAUCET Risk Score of 89/100, significant community discussion (8 mentions), and media coverage (7 articles) indicate considerable attention and potential for future exploitation, including discussions around NTLM v2 hash theft.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:-:*:-:*:-:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:*:* | ||
2021CPE matchmatch criteria | cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.