# Outlook reminder leaks Net-NTLMv2 hashes with no click

Source: https://startwithidentity.com/cves/cve-2023-23397/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

Outlook for Windows honored `PidLidReminderFileParameter` on a meeting. An attacker set that property to a UNC path they controlled. When the reminder fired, Outlook authenticated to the share and sent a Net-NTLMv2 hash. No click, no preview pane. All supported Outlook-for-Windows builds, including Microsoft 365. Exploited as a zero-day. CISA KEV. Patched 14 March 2023.

## Why it matters

NTLM hashes are still passwords in many forests. A calendar invite that steals them is an identity incident that starts in email. Russian state actors used it. Identity teams who had "we blocked NTLM outbound" as a control found out who actually had that control.

## What to do

- Deploy the March 2023 Outlook updates. Hunt for messages that set `PidLidReminderFileParameter` (Microsoft published a script).
- Block outbound SMB/WebDAV from workstations. Disable NTLM where you can.
- If hashes could have left the network, treat them as compromised passwords: reset, and look for later use.

## After you patch

Patching an authentication bypass stops new intrusions. It does not evict anyone already inside, and that is the step most teams skip.

- **Revoke every session and [refresh token](https://startwithidentity.com/glossary/refresh-token/)**, not just the passwords. A session issued before the patch is still valid after it.
- **Enumerate accounts created or modified during the exposure window**, including local accounts on the appliance itself, service accounts, and API tokens.
- **Remove authentication methods you did not add.** An attacker with administrative access enrols a factor so the access survives your remediation.
- **Rotate every credential the compromised system could reach**: directory service accounts used for user lookup, integration keys, and anything in its configuration store. See [secrets rotation](https://startwithidentity.com/glossary/secrets-rotation/).
- **Assume the device is a pivot, not a destination.** Check what it could authenticate to and treat that as in scope.

## Sources

- [NVD: CVE-2023-23397](https://nvd.nist.gov/vuln/detail/CVE-2023-23397)
- CISA KEV
- Huntress / Microsoft guidance, March 2023
