← All detection heuristics · CVE
critical
CVE_2023_23397
What it means
Outlook .msg contains UNC reminder evidence: exact for ReminderFileParameter, related for raw UNC fallback.
Why it fires
CVE-2023-23397 is a critical Microsoft Outlook privilege escalation / credential theft vulnerability with CVSS 9.8. An attacker sends a specially crafted meeting request, task, or appointment where the PidLidReminderFileParameter property contains a UNC path pointing to an attacker-controlled server. When Outlook processes the item (even before the user opens it), Windows automatically authenticates to the remote server using NTLM, leaking the victim's Net-NTLMv2 hash. This hash can be cracked offline or used in relay attacks for lateral movement across the network. The sandboxed MSG parser matches the ReminderFileParameter property stream and marks this exact when it contains a UNC path; fallback raw-byte UNC evidence remains related.
Other CVE heuristics
CVE_2026_34621_RELATED CVE_2023_26369 CVE_2026_34621 CVE_2010_1297_FLASH_RICHMEDIA CVE_2010_1297_SWF_TRIGGER CVE_2011_0611_SWF_TRIGGER CVE_2009_1862_FLASH_RICHMEDIA CVE_2010_2883 CVE_2018_4901 CVE_2009_3459 CVE_2018_4990_JPX_EMBEDDED_CMD CVE_2018_4990_JPX_CMAP_TRIGGER CVE_2010_1240 CVE_2010_0188 CVE_2014_0514 CVE_2013_3346 CVE_2013_0640 CVE_2010_3654_FLASH_RICHMEDIA CVE_2007_5020_MAILTO_MSHTA CVE_2014_0496 CVE_2008_2551 CVE_2021_40444 CVE_2006_4694 CVE_2008_0118