PatchSiren cyber security CVE debrief
CVE-2023-35311 Microsoft CVE debrief
CVE-2023-35311 is a Microsoft Outlook security feature bypass vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied sources confirm known exploitation and direct defenders to apply Microsoft updates as soon as possible, or discontinue use of the product if updates are unavailable. Because the source corpus does not include affected versions or exploit mechanics, the main action is operational prioritization rather than deep technical validation.
- Vendor
- Microsoft
- Product
- Outlook
- CVSS
- HIGH 8.8
- CISA KEV
- Listed
- Original CVE published
- 2023-07-11
- Original CVE updated
- 2023-07-11
- Advisory published
- 2023-07-11
- Advisory updated
- 2023-07-11
Who should care
Microsoft Outlook administrators, endpoint and email security teams, patch management owners, vulnerability management teams, and incident response staff responsible for internet-facing or widely deployed Windows productivity environments.
Technical summary
The supplied corpus identifies CVE-2023-35311 as a Microsoft Outlook security feature bypass vulnerability. CISA’s KEV entry confirms it as known exploited and includes Microsoft’s update-guide link in the notes, but the provided sources do not disclose affected versions, attack preconditions, or exploit steps. Treat the issue as a high-priority remediation item because it is on the KEV catalog with a required action to apply vendor updates or discontinue use if updates are unavailable.
Defensive priority
High. The vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog and has a KEV due date of 2023-08-01 in the supplied timeline, so remediation should be expedited.
Recommended defensive actions
- Apply Microsoft’s recommended updates for CVE-2023-35311 using the vendor guidance referenced in the KEV notes.
- Confirm whether Microsoft Outlook is deployed in your environment and map the exposure of affected systems and users.
- Track remediation against the CISA KEV due date of 2023-08-01 and escalate any unpatched instances.
- If updates cannot be applied promptly, follow the KEV-required action and discontinue use of the product where feasible until remediation is complete.
- Validate patch status through centralized vulnerability and asset management rather than relying on manual reports alone.
Evidence notes
The supplied corpus contains a CISA KEV entry dated 2023-07-11 naming this issue as a Microsoft Outlook Security Feature Bypass Vulnerability, with a required action to apply vendor updates or discontinue use if updates are unavailable. The KEV metadata marks knownRansomwareCampaignUse as Unknown. The notes cite Microsoft’s MSRC update guide and the NVD record, but the corpus itself does not provide CVSS, affected versions, or exploit mechanics.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-35311 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-35311
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-35311 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-35311
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.