July 11, 2023 · Applied Cybernetics Group
CVE-2023-35311 — Microsoft Outlook
Microsoft Outlook Security Feature Bypass Vulnerability
- Added to KEV
2023-07-11- Federal due date
2023-08-01- Vendor
- Microsoft
- Product
- Outlook
- EPSS
- 65.2th percentile (score 0.005, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2023-35311
CISA short description
Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.
Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.