CVE-2023-35311: Microsoft Outlook Security Feature Bypass Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2023-07-11. EPSS: 15.5% chance of exploitation in the next 30 days.

Microsoft Outlook Security Feature Bypass Vulnerability

Affected products

  • Microsoft 365 Apps: affected versions not specified
  • Microsoft Office 2019: affected versions not specified
  • Microsoft Office 2021: affected versions not specified
  • Microsoft Outlook: version 2013 only; version 2016 only

Published 2023-07-11. Last modified 2026-10-08.