Lucene search

K
cveMicrosoftCVE-2023-33151
HistoryJul 11, 2023 - 6:15 p.m.

CVE-2023-33151

2023-07-1118:15:14
microsoft
web.nvd.nist.gov
72
microsoft
outlook
spoofing
vulnerability
cve-2023-33151
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

47.2%

Microsoft Outlook Spoofing Vulnerability

Affected configurations

Nvd
Vulners
Node
microsoft365_appsMatch-enterprisex64
OR
microsoft365_appsMatch-enterprisex86
OR
microsoftofficeMatch2013sp1x64
OR
microsoftofficeMatch2013sp1x86
OR
microsoftofficeMatch2013sp1rt
OR
microsoftofficeMatch2016x64
OR
microsoftofficeMatch2016x86
OR
microsoftofficeMatch2019-x64
OR
microsoftofficeMatch2019-x86
OR
microsoftofficeMatch2021ltscx64
OR
microsoftofficeMatch2021ltscx86
VendorProductVersionCPE
microsoft365_apps-cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x64:*
microsoft365_apps-cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:x86:*
microsoftoffice2013cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:x64:*
microsoftoffice2013cpe:2.3:a:microsoft:office:2013:sp1:*:*:*:*:x86:*
microsoftoffice2013cpe:2.3:a:microsoft:office:2013:sp1:*:*:rt:*:*:*
microsoftoffice2016cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x64:*
microsoftoffice2016cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x86:*
microsoftoffice2019cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:x64:*
microsoftoffice2019cpe:2.3:a:microsoft:office:2019:*:*:*:*:-:x86:*
microsoftoffice2021cpe:2.3:a:microsoft:office:2021:*:*:*:ltsc:*:x64:*
Rows per page:
1-10 of 111

CNA Affected

[
  {
    "vendor": "Microsoft",
    "product": "Microsoft Office LTSC 2021",
    "cpes": [
      "cpe:2.3:a:microsoft:office_long_term_servicing_channel:2021:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "x64-based Systems",
      "32-bit Systems"
    ],
    "versions": [
      {
        "version": "16.0.1",
        "lessThan": "https://aka.ms/OfficeSecurityReleases",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft 365 Apps for Enterprise",
    "cpes": [
      "cpe:2.3:a:microsoft:365_apps:-:*:*:*:enterprise:*:*:*"
    ],
    "platforms": [
      "x64-based Systems",
      "32-bit Systems"
    ],
    "versions": [
      {
        "version": "16.0.1",
        "lessThan": "https://aka.ms/OfficeSecurityReleases",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft Outlook 2016",
    "cpes": [
      "cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:x64:*:*",
      "cpe:2.3:a:microsoft:outlook:2016:*:*:*:*:x86:*:*"
    ],
    "platforms": [
      "x64-based Systems",
      "32-bit Systems"
    ],
    "versions": [
      {
        "version": "16.0.0.0",
        "lessThan": "16.0.5404.1000",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft Office 2019",
    "cpes": [
      "cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "32-bit Systems",
      "x64-based Systems"
    ],
    "versions": [
      {
        "version": "19.0.0",
        "lessThan": "https://aka.ms/OfficeSecurityReleases",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft Outlook 2013",
    "cpes": [
      "cpe:2.3:a:microsoft:outlook:2013:-:-:*:-:-:x86:*",
      "cpe:2.3:a:microsoft:outlook:2013:-:-:*:-:-:x64:*"
    ],
    "platforms": [
      "32-bit Systems",
      "x64-based Systems"
    ],
    "versions": [
      {
        "version": "14.0.0",
        "lessThan": "15.0.5571.1000",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft Outlook 2013 Service Pack 1",
    "cpes": [
      "cpe:2.3:a:microsoft:outlook:2013:*:*:*:rt:*:*:*"
    ],
    "platforms": [
      "ARM64-based Systems"
    ],
    "versions": [
      {
        "version": "15.0.0.0",
        "lessThan": "15.0.5571.1000",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

47.2%