CISA Known Exploited Vulnerability

CVE-2023-35311

Microsoft · Outlook

Microsoft Outlook Security Feature Bypass Vulnerability

Date added
BOD 22-01 due date
CWE CWE-367
Ransomware Unknown

CISA description

Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.

Required action

Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.