CVE-2023-35311
Microsoft Outlook Security Feature Bypass Vulnerability
Description
CVE-2023-35311 is a security feature bypass vulnerability in Microsoft Outlook that exploits a time-of-check to time-of-use (TOCTOU) race condition to circumvent built-in security prompts. This vulnerability allows an attacker to bypass Microsoft Outlook's security feature dialogs, enabling malicious content to be processed without the expected user warnings. The flaw affects Microsoft Outlook, Microsoft 365 Apps, Microsoft Office, and Microsoft Office Long Term Servicing Channel editions. CISA has added CVE-2023-35311 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, making it a priority for immediate patching across enterprise environments.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | 365 apps | - |
| microsoft | office | 2019 |
| microsoft | office long term servicing channel | 2021 |
| microsoft | outlook | 2013; 2016 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35311(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-35311(US Government Resource)
Weakness Type
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
In CVE-2023-35311, a TOCTOU race condition in Microsoft Outlook allows an attacker to manipulate the state of a resource between the time it is validated (checked) and the time it is used, effectively bypassing security feature prompts that would normally warn users about potentially dangerous content.
Learn more: CWE-367 — Time-of-check Time-of-use (TOCTOU) Race Condition
Impact Analysis
CVE-2023-35311 carries a HIGH severity rating with a CVSS v3.1 score of 8.8, indicating a substantial security risk. The vulnerability is remotely exploitable without physical access through a network-based attack vector, and the attack complexity is low, requiring no special conditions or timing for exploitation. No authentication is needed to initiate the attack, though user interaction is required — the victim must interact with a malicious email or link within Microsoft Outlook. Successful exploitation results in high impact across confidentiality, integrity, and availability, as bypassing Outlook's security prompts can enable the delivery and execution of malicious payloads, potentially leading to data theft, system compromise, or unauthorized access to email communications. Although the EPSS score of 0.5% is relatively low, the confirmed active exploitation in CISA's KEV catalog underscores that this vulnerability is being used by threat actors in real-world attacks.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2023-35311 in the wild by adding it to the Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of August 1, 2023. Despite a relatively low EPSS score of 0.5% (64th percentile), the confirmed KEV status demonstrates that targeted exploitation is occurring. No public exploit code is tagged in the NVD references, suggesting the vulnerability may be leveraged through targeted or sophisticated attack campaigns rather than widely available exploit tools.
Remediation
- Apply Microsoft security updates immediately as directed by CISA's KEV required action: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Install the July 2023 patches from the Microsoft Security Update Guide.
- Update all affected Microsoft products, including Microsoft Outlook, Microsoft 365 Apps, Microsoft Office, and Microsoft Office Long Term Servicing Channel (LTSC) installations. Ensure both Click-to-Run and MSI-based installations are patched.
- Restrict external email content by configuring Outlook security settings to block automatic preview of external content, disable automatic download of external images, and enforce Protected View for attachments received from external senders.
- Monitor for indicators of compromise by reviewing Outlook-related security logs for unusual behavior patterns such as suppressed security prompts, unexpected attachment processing, or suspicious email-triggered process execution. Deploy endpoint detection rules targeting Outlook exploitation techniques.
- Implement email security hardening by enabling Safe Attachments and Safe Links policies in Microsoft Defender for Office 365, configuring anti-phishing policies, and deploying email authentication standards (SPF, DKIM, DMARC) to reduce the likelihood of malicious emails reaching user inboxes.
Technical Details
CVE-2023-35311 is rooted in a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) within Microsoft Outlook's security validation mechanism. The vulnerability arises when Outlook checks whether certain content should trigger a security warning prompt but the underlying resource state changes between this validation check and the subsequent use of the content, allowing the security prompt to be bypassed entirely. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates that the attack can be launched remotely over the network with low complexity and without any authentication, though user interaction is required — typically in the form of opening a crafted email or clicking a malicious link. The race condition effectively turns Outlook's security prompts into unreliable guards, allowing an attacker to deliver payloads that would normally be blocked or flagged for user approval.
Frequently Asked Questions
Is CVE-2023-35311 being actively exploited?
Yes, CVE-2023-35311 is being actively exploited in the wild. CISA has included this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 1, 2023. Organizations should prioritize patching immediately.
What products are affected by CVE-2023-35311?
CVE-2023-35311 affects Microsoft Outlook, Microsoft 365 Apps, Microsoft Office, and Microsoft Office Long Term Servicing Channel (LTSC) editions. All organizations using these products should apply the available security updates.
How do I fix CVE-2023-35311?
Apply the July 2023 security updates from Microsoft via the Microsoft Security Update Guide. Update all affected Outlook and Office installations, including both Click-to-Run and MSI-based deployments. See the Remediation section for additional hardening steps.
How severe is CVE-2023-35311?
CVE-2023-35311 is rated HIGH severity with a CVSS v3.1 score of 8.8 out of 10. While the EPSS score is 0.5% (64th percentile), the confirmed active exploitation by CISA demonstrates real-world risk. The vulnerability bypasses security prompts in Outlook, potentially allowing malicious payloads to execute without user awareness.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.