PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-35311 Microsoft CVE debrief

CVE-2023-35311 is a Microsoft Outlook security feature bypass vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied sources confirm known exploitation and direct defenders to apply Microsoft updates as soon as possible, or discontinue use of the product if updates are unavailable. Because the source corpus does not include affected versions or exploit mechanics, the main action is operational prioritization rather than deep technical validation.

Vendor
Microsoft
Product
Outlook
CVSS
HIGH 8.8
CISA KEV
Listed
Original CVE published
2023-07-11
Original CVE updated
2023-07-11
Advisory published
2023-07-11
Advisory updated
2023-07-11

Who should care

Microsoft Outlook administrators, endpoint and email security teams, patch management owners, vulnerability management teams, and incident response staff responsible for internet-facing or widely deployed Windows productivity environments.

Technical summary

The supplied corpus identifies CVE-2023-35311 as a Microsoft Outlook security feature bypass vulnerability. CISA’s KEV entry confirms it as known exploited and includes Microsoft’s update-guide link in the notes, but the provided sources do not disclose affected versions, attack preconditions, or exploit steps. Treat the issue as a high-priority remediation item because it is on the KEV catalog with a required action to apply vendor updates or discontinue use if updates are unavailable.

Defensive priority

High. The vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog and has a KEV due date of 2023-08-01 in the supplied timeline, so remediation should be expedited.

Recommended defensive actions

  • Apply Microsoft’s recommended updates for CVE-2023-35311 using the vendor guidance referenced in the KEV notes.
  • Confirm whether Microsoft Outlook is deployed in your environment and map the exposure of affected systems and users.
  • Track remediation against the CISA KEV due date of 2023-08-01 and escalate any unpatched instances.
  • If updates cannot be applied promptly, follow the KEV-required action and discontinue use of the product where feasible until remediation is complete.
  • Validate patch status through centralized vulnerability and asset management rather than relying on manual reports alone.

Evidence notes

The supplied corpus contains a CISA KEV entry dated 2023-07-11 naming this issue as a Microsoft Outlook Security Feature Bypass Vulnerability, with a required action to apply vendor updates or discontinue use if updates are unavailable. The KEV metadata marks knownRansomwareCampaignUse as Unknown. The notes cite Microsoft’s MSRC update guide and the NVD record, but the corpus itself does not provide CVSS, affected versions, or exploit mechanics.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-35311 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-35311

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-35311 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-35311

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.