Identity CVE · Other
CVE-2023-23397Outlook reminder leaks Net-NTLMv2 hashes with no click
critical · CVSS 9.8CISA KEVActively exploited
Product: Microsoft Outlook for WindowsVendor: MicrosoftCWE-294Disclosed: 2023-03-14Status: Actively exploitedNVD ↗CISA KEV ↗
What broke
Outlook for Windows honored PidLidReminderFileParameter on a meeting. An attacker set that property to a UNC path they controlled. When the reminder fired, Outlook authenticated to the share and sent a Net-NTLMv2 hash. No click, no preview pane. All supported Outlook-for-Windows builds, including Microsoft 365. Exploited as a zero-day. CISA KEV. Patched 14 March 2023.
Why it matters
NTLM hashes are still passwords in many forests. A calendar invite that steals them is an identity incident that starts in email. Russian state actors used it. Identity teams who had "we blocked NTLM outbound" as a control found out who actually had that control.
What to do
- Deploy the March 2023 Outlook updates. Hunt for messages that set
PidLidReminderFileParameter(Microsoft published a script). - Block outbound SMB/WebDAV from workstations. Disable NTLM where you can.
- If hashes could have left the network, treat them as compromised passwords: reset, and look for later use.
Sources
- NVD: CVE-2023-23397
- CISA KEV
- Huntress / Microsoft guidance, March 2023
Related identity CVEs
Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.