
CVE-2023-23397 Outlook: Zero-Click NTLM Hash Theft
CVE-2023-23397 is a critical privilege escalation and credential theft vulnerability in Microsoft Outlook for Windows. A specially crafted calendar invitation with a UNC path in the reminder sound field causes Outlook to automatically connect to an attacker-controlled SMB server, leaking the victim's NTLM authentication hash. No user interaction is required, the exploit fires when the reminder triggers, even if the meeting invitation is never opened.

