CVE-2023-33151
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2023-33151 is a new Microsoft Outlook spoofing vulnerability that has been disclosed. This issue allows an attacker to manipulate the email preview text in Outlook, potentially tricking users into revealing sensitive information or clicking on malicious links. The attack does not require user interaction or advanced technical skills, making it a significant threat to organizations and individuals using Microsoft Outlook. The vulnerability exists due to insufficient input validation in the email preview functionality, allowing an attacker to inject malicious content into the preview text. Microsoft has released a patch to address the issue, and users are encouraged to update their Outlook software as soon as possible to protect against potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Office
- Microsoft 365 Apps
Affected Vendors
- Microsoft