CVE-2023-35311

HIGH(8.8)KEVElevated Risk

Microsoft Outlook Security Feature Bypass Vulnerability

Description

CVE-2023-35311 is a security feature bypass vulnerability in Microsoft Outlook that exploits a time-of-check to time-of-use (TOCTOU) race condition to circumvent built-in security prompts. This vulnerability allows an attacker to bypass Microsoft Outlook's security feature dialogs, enabling malicious content to be processed without the expected user warnings. The flaw affects Microsoft Outlook, Microsoft 365 Apps, Microsoft Office, and Microsoft Office Long Term Servicing Channel editions. CISA has added CVE-2023-35311 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, making it a priority for immediate patching across enterprise environments.

KEV Information

Vendor
Microsoft
Product
Outlook
Date Added
July 11, 2023
Due Date
August 1, 2023
Required Action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
microsoft365 apps-
microsoftoffice2019
microsoftoffice long term servicing channel2021
microsoftoutlook2013; 2016

Multiple CVSS Assessments

Source: [email protected](Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Source: [email protected](Secondary)
7.5
HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.5
HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition

In CVE-2023-35311, a TOCTOU race condition in Microsoft Outlook allows an attacker to manipulate the state of a resource between the time it is validated (checked) and the time it is used, effectively bypassing security feature prompts that would normally warn users about potentially dangerous content.

Learn more: CWE-367 — Time-of-check Time-of-use (TOCTOU) Race Condition

Impact Analysis

CVE-2023-35311 carries a HIGH severity rating with a CVSS v3.1 score of 8.8, indicating a substantial security risk. The vulnerability is remotely exploitable without physical access through a network-based attack vector, and the attack complexity is low, requiring no special conditions or timing for exploitation. No authentication is needed to initiate the attack, though user interaction is required — the victim must interact with a malicious email or link within Microsoft Outlook. Successful exploitation results in high impact across confidentiality, integrity, and availability, as bypassing Outlook's security prompts can enable the delivery and execution of malicious payloads, potentially leading to data theft, system compromise, or unauthorized access to email communications. Although the EPSS score of 0.5% is relatively low, the confirmed active exploitation in CISA's KEV catalog underscores that this vulnerability is being used by threat actors in real-world attacks.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2023-35311 in the wild by adding it to the Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of August 1, 2023. Despite a relatively low EPSS score of 0.5% (64th percentile), the confirmed KEV status demonstrates that targeted exploitation is occurring. No public exploit code is tagged in the NVD references, suggesting the vulnerability may be leveraged through targeted or sophisticated attack campaigns rather than widely available exploit tools.

Remediation

  1. Apply Microsoft security updates immediately as directed by CISA's KEV required action: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Install the July 2023 patches from the Microsoft Security Update Guide.
  2. Update all affected Microsoft products, including Microsoft Outlook, Microsoft 365 Apps, Microsoft Office, and Microsoft Office Long Term Servicing Channel (LTSC) installations. Ensure both Click-to-Run and MSI-based installations are patched.
  3. Restrict external email content by configuring Outlook security settings to block automatic preview of external content, disable automatic download of external images, and enforce Protected View for attachments received from external senders.
  4. Monitor for indicators of compromise by reviewing Outlook-related security logs for unusual behavior patterns such as suppressed security prompts, unexpected attachment processing, or suspicious email-triggered process execution. Deploy endpoint detection rules targeting Outlook exploitation techniques.
  5. Implement email security hardening by enabling Safe Attachments and Safe Links policies in Microsoft Defender for Office 365, configuring anti-phishing policies, and deploying email authentication standards (SPF, DKIM, DMARC) to reduce the likelihood of malicious emails reaching user inboxes.

Technical Details

CVE-2023-35311 is rooted in a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) within Microsoft Outlook's security validation mechanism. The vulnerability arises when Outlook checks whether certain content should trigger a security warning prompt but the underlying resource state changes between this validation check and the subsequent use of the content, allowing the security prompt to be bypassed entirely. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates that the attack can be launched remotely over the network with low complexity and without any authentication, though user interaction is required — typically in the form of opening a crafted email or clicking a malicious link. The race condition effectively turns Outlook's security prompts into unreliable guards, allowing an attacker to deliver payloads that would normally be blocked or flagged for user approval.

Frequently Asked Questions

Is CVE-2023-35311 being actively exploited?

Yes, CVE-2023-35311 is being actively exploited in the wild. CISA has included this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 1, 2023. Organizations should prioritize patching immediately.

What products are affected by CVE-2023-35311?

CVE-2023-35311 affects Microsoft Outlook, Microsoft 365 Apps, Microsoft Office, and Microsoft Office Long Term Servicing Channel (LTSC) editions. All organizations using these products should apply the available security updates.

How do I fix CVE-2023-35311?

Apply the July 2023 security updates from Microsoft via the Microsoft Security Update Guide. Update all affected Outlook and Office installations, including both Click-to-Run and MSI-based deployments. See the Remediation section for additional hardening steps.

How severe is CVE-2023-35311?

CVE-2023-35311 is rated HIGH severity with a CVSS v3.1 score of 8.8 out of 10. While the EPSS score is 0.5% (64th percentile), the confirmed active exploitation by CISA demonstrates real-world risk. The vulnerability bypasses security prompts in Outlook, potentially allowing malicious payloads to execute without user awareness.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score15.52%
EPSS Percentile96.5%

Dates

PublishedJuly 11, 2023
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.