{"id":51103,"date":"2023-03-21T00:00:00","date_gmt":"2023-03-21T00:00:00","guid":{"rendered":"urn:uuid:d46d012a-745e-81b6-e15d-62ae5a0bdca0"},"modified":"2023-03-21T00:00:00","modified_gmt":"2023-03-21T00:00:00","slug":"patch-cve-2023-23397-immediately-what-you-need-to-know-and-do","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/","title":{"rendered":"Patch CVE-2023-23397 Immediately: What You Need To Know and Do"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/23\/patch-cve-2023-23397-immediately-what-you-need-to-know-do-cover.jpg\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/23\/patch-cve-2023-23397-immediately-what-you-need-to-know-do-cover.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<div readability=\"50.780516431925\">\n<div readability=\"46.797730829421\">\n<p><span class=\"body-subhead-title\">How is CVE-2023-23397 exploited?<\/span><\/p>\n<p>The attacker sends a message to the victim with an extended Message Application Program Interface (MAPI) property with a Universal Naming Convention (UNC) path to a remote attacker-controlled Server Message Block (SMB, via TCP 445). Share-hosted on a server controlled by the attacker, the vulnerability is exploited whether the recipient has seen the message or not. The attacker remotely sends a malicious calendar invite represented by .msg \u2014 the message format that supports reminders in Outlook \u2014 to trigger the vulnerable API endpoint PlayReminderSound using \u201cPidLidReminderFileParameter\u201d (the custom alert sound option for reminders).<\/p>\n<p>When the victim connects to the attacker\u2019s SMB server, the connection to the remote server sends the user\u2019s New Technology LAN Manager (<a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/security\/kerberos\/ntlm-overview\">NTLM<\/a>) negotiation message automatically, which the attacker can use for authentication against other systems that support NTLM authentication.<\/p>\n<p>NTLMv2 hashes are the latest protocol Windows uses for authentication, and it is used for a number of services with each response containing a hashed representation of users\u2019 information, such as the username and password. As such, threat actors can attempt a NTLM relay attack to gain access to other services, or a full compromise of domains if the compromised users are admins. While online services such as Microsoft 365 are not susceptible to this attack because they do not support NTLM authentication, the Microsoft 365 Windows Outlook app is still vulnerable.<\/p>\n<p>User interaction is not&nbsp;necessary to trigger (even before message&nbsp;preview) it, nor does it require high privileges. CVE-2023-23397 is a zero-touch vulnerability that is triggered when the victim client is prompted and notified (e.g., when an appointment or task prompts five minutes before the designated time). It is difficult to block outbound SMB traffic for&nbsp;remote users. The attacker could use the same credentials to gain access to other resources. We elaborate on this example in our <a href=\"https:\/\/www.youtube.com\/watch?v=j44vIhklTp4\">webinar<\/a> (at 04:23 of the video).<\/p>\n<p>There have been reports of limited attacks abusing this gap. Microsoft has been coordinating with the affected victims to remediate this concern. All supported versions of Microsoft Outlook for Windows are affected. Other versions of Microsoft Outlook, such as Android, iOS, Mac, as well as Outlook on the web and other M365 services, are not affected.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31.303370786517\">\n<div readability=\"13.415730337079\">\n<p>1. Lateral movement, malicious navigation using the relayed NTLM hashes<\/p>\n<p>Relay attacks gained notoriety as a use case for <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/HackTool.Win32.MIMIKATZ.SMGD\/\">Mimikatz<\/a> using the NTLM credential dumping routine via the <a href=\"https:\/\/tools.thehacker.recipes\/mimikatz\/modules#sekurlsa\">sekurlsa<\/a> module. In addition, <a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=36036\">pass-the-hat (PtH)<\/a> (or <a href=\"https:\/\/www.thehacker.recipes\/ad\/movement\/ntlm\/pth\">pass-the hash<\/a>) attacks and variations of data and information theft can be done. Once attackers are in the system, they can use the network for lateral movement and navigate the organization\u2019s lines over SMB.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"40.627563781891\">\n<div readability=\"29.886943471736\">\n<p>2. WebDAV directory traversal for payload attacker routines<\/p>\n<p>It\u2019s possible for an attacker to leverage <a href=\"https:\/\/learn.microsoft.com\/en-us\/iis\/configuration\/system.webserver\/webdav\/\">WebDAV<\/a> services in cases where no valid SMB service for Outlook exists (i.e., is not configured) in the client. This is an alternative to the Web\/HTTP service that can also be read as a UNC path by .msg and\/or Outlook Calendar items. Attackers can set up a malicious WebDAV server to respond to affected victim clients with malicious pages. These pages may contain code that can range from leveraging a directory traversal technique similar to the Microsoft vulnerability <a href=\"https:\/\/github.com\/ariary\/DogWalk-rce-poc\/blob\/master\/webdav\/diagcab-webdav-poc\/diagcab-webdav-poc.pl\">CVE-2022-34713<\/a> (dubbed as <a href=\"https:\/\/success.trendmicro.com\/dcx\/s\/solution\/000291380?language=en_US&amp;sfdcIFrameOrigin=null\">DogWalk<\/a>) to push any form of payload for remote code execution such as webshells.<\/p>\n<p>Here are some steps that security administrators can perform to reduce the risk of exploitation of CVE-2023-23397:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Apply the vendor patches immediately.<\/b> Microsoft has released a <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-23397\">patch<\/a> as part of their March 2023 Monthly Security Update.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Block TCP 445\/SMB outbound from your network. <\/b>This will prevent the sending of NTLM authentication messages to remote file shares. If this cannot be done, we recommend monitoring outbound traffic over port 445 for unknown external IP addresses, then identifying and blocking them.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Customers can disable the WebClient service. <\/b>Note that this will block all WebDAV connections, including intranet.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Add users to the Protected Users Security Group.<\/b> This prevents the use of NTLM as an authentication mechanism, but note that this could impact applications that rely on NTLM in your environment.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Enforce SMB signing on clients and servers <\/b>to prevent a relay attack.<\/span><\/li>\n<\/ul>\n<p>Microsoft has provided a PowerShell script as a solution to the issue. The script is designed to scan emails, calendar entries, and task items, and to verify if they have the \u201cPidLidReminderFileParameter\u201d property. By running the script, administrators can locate problematic items that have this property and subsequently remove them or delete them permanently. Download the script here: <a href=\"https:\/\/github.com\/microsoft\/CSS-Exchange\/blob\/a4c096e8b6e6eddeba2f42910f165681ed64adf7\/docs\/Security\/CVE-2023-23397.md\" title=\"https:\/\/github.com\/microsoft\/css-exchange\/blob\/a4c096e8b6e6eddeba2f42910f165681ed64adf7\/docs\/security\/cve-2023-23397.md\">https:\/\/github.com\/microsoft\/CSS-Exchange\/blob\/a4c096e8b6e6eddeba2f42910f165681ed64adf7\/docs\/Security\/CVE-2023-23397.md<\/a>.<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><\/span>Trend Micro Malware Detection Patterns (VSAPI, Predictive Learning, Behavioral Monitoring and Web Reputation Service) for Endpoint, Servers, Mail, and Gateway (e.g., Apex One, Worry-Free Business Security Services, Worry-Free Business Security Standard\/Advanced, Deep Security with anti-malware, etc.):\n<ul>\n<li><span class=\"rte-circle-bullet\"><\/span>Starting with Trend Micro Smart Scan Pattern version 21474.296.07, known exploits associated with this vulnerability are being detected as&nbsp;<i>Trojan.Win32.CVE202323397<\/i>.<\/li>\n<\/ul>\n<\/li>\n<li><span class=\"rte-red-bullet\"><\/span>Trend Micro Vision One: Use this solution as an investigation tool. In the \u201cSearch App,\u201d select \u201cEndpoint Activity Data\u201d and enter&nbsp;the following query: <i>&#8211; dpt: 445 AND eventSubId: 204 AND processCmd: *OUTLOOK*<\/i>. This can be saved and added to a watchlist if desired.<\/li>\n<li><span class=\"rte-red-bullet\">Cloud One Workload Security and Deep Security: IPS Rule 1009058, which will need to be&nbsp;changed to Prevent.&nbsp;<\/span><\/li>\n<li><span class=\"rte-red-bullet\">TippingPoint Filters:<\/span>\n<ul>\n<li><span class=\"rte-circle-bullet\">28471 SMB: SMBv1 Successful Protocol Negotiation<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">28472 SMB:&nbsp;SMBv2 Successful Protocol Negotiation<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">Please note: Enabling these filters in Block mode&nbsp;will interrupt legitimate SMB traffic. Customers are advised to add exceptions for their&nbsp;Private IP address space.<\/span><\/li>\n<\/ul>\n<\/li>\n<li><span class=\"rte-red-bullet\"><\/span>Trend Micro Deep Discovery Inspector: Rule 4479 NTLM v1 Authentication &#8211; SMB (Request).\n<ul>\n<li><span class=\"rte-circle-bullet\"><\/span>If NTLM&nbsp;v1 is configured by default, customers can use this rule to monitor attempts for&nbsp;outgoing NTLM handshakes. Please note this rule only detects and does not block, so it is best used as an investigative tool for follow-up.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Details for all available Trend Micro solutions are available here: <a href=\"https:\/\/success.trendmicro.com\/dcx\/s\/solution\/000292525?language=en_US\">https:\/\/success.trendmicro.com\/dcx\/s\/solution\/000292525?language=en_US<\/a>.<\/p>\n<p>To learn more about this vulnerability, you may view our technical webinar here: <a href=\"https:\/\/www.youtube.com\/watch?v=j44vIhklTp4\">https:\/\/www.youtube.com\/watch?v=j44vIhklTp4<\/a><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p>Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/c\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We break down the basic information of CVE-2023-23397, the zero-day, zero-touch vulnerability that was rated 9.8 on the Common Vulnerability Scoring System (CVSS) scale. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":51104,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9546,9510,9520,9511,9565,9508,9555,9523],"class_list":["post-51103","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-apttargeted-attacks","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-cloud","tag-trend-micro-research-cyber-threats","tag-trend-micro-research-data-center","tag-trend-micro-research-endpoints","tag-trend-micro-research-exploitsvulnerabilities","tag-trend-micro-research-network"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Patch CVE-2023-23397 Immediately: What You Need To Know and Do 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Patch CVE-2023-23397 Immediately: What You Need To Know and Do 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-03-21T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/23\/patch-cve-2023-23397-immediately-what-you-need-to-know-do-cover.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Patch CVE-2023-23397 Immediately: What You Need To Know and Do\",\"datePublished\":\"2023-03-21T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\\\/\"},\"wordCount\":1043,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do.jpg\",\"keywords\":[\"Trend Micro Research : APT&amp;Targeted Attacks\",\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Cloud\",\"Trend Micro Research : Cyber Threats\",\"Trend Micro Research : Data center\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Exploits&amp;Vulnerabilities\",\"Trend Micro Research : Network\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\\\/\",\"name\":\"Patch CVE-2023-23397 Immediately: What You Need To Know and Do 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do.jpg\",\"datePublished\":\"2023-03-21T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do.jpg\",\"width\":641,\"height\":350},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : APT&amp;Targeted Attacks\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-apttargeted-attacks\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Patch CVE-2023-23397 Immediately: What You Need To Know and Do\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Patch CVE-2023-23397 Immediately: What You Need To Know and Do 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/","og_locale":"en_US","og_type":"article","og_title":"Patch CVE-2023-23397 Immediately: What You Need To Know and Do 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-03-21T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/23\/patch-cve-2023-23397-immediately-what-you-need-to-know-do-cover.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Patch CVE-2023-23397 Immediately: What You Need To Know and Do","datePublished":"2023-03-21T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/"},"wordCount":1043,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/03\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do.jpg","keywords":["Trend Micro Research : APT&amp;Targeted Attacks","Trend Micro Research : Articles, News, Reports","Trend Micro Research : Cloud","Trend Micro Research : Cyber Threats","Trend Micro Research : Data center","Trend Micro Research : Endpoints","Trend Micro Research : Exploits&amp;Vulnerabilities","Trend Micro Research : Network"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/","url":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/","name":"Patch CVE-2023-23397 Immediately: What You Need To Know and Do 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/03\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do.jpg","datePublished":"2023-03-21T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/03\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/03\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do.jpg","width":641,"height":350},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/patch-cve-2023-23397-immediately-what-you-need-to-know-and-do\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : APT&amp;Targeted Attacks","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-apttargeted-attacks\/"},{"@type":"ListItem","position":3,"name":"Patch CVE-2023-23397 Immediately: What You Need To Know and Do"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/51103","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=51103"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/51103\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/51104"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=51103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=51103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=51103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}