Update now – Microsoft Outlook for Windows critical security vulnerability (CVE-2023-23397)
We’ve been made aware of a new critical vulnerability within the Microsoft Outlook email client for Windows. Microsoft has already released a patch for this, and we recommend updating your version of Outlook at the earliest opportunity.
More information on the vulnerability can be found here. And more information from Microsoft on what has happened can be found here.
All supported versions of Microsoft Outlook for Windows are affected. Other versions of Microsoft Outlook such as Android, iOS, Mac, as well as Outlook on the web and other M365 services are not affected.
To upgrade your version of Outlook on Windows, please do the following:
- In Outlook click File
- Select Office Account on the left-hand menu
- Click Update Options > Update Now
These are the patched, and therefore safe-to-use versions of Outlook are:
- Current channel – Version 2303 (Build 16130.20306)
- Monthly enterprise channel – Version 2301 (Build 16026.20238) or Version 2212 (Build 154928.20298)
- Semi-annual enterprise channel (Preview) – Version 2302 (Build 16130.20306)
- Semi-annual enterprise channel – Version 2208 (Build 15601.20578) or Version 2202 (Build 14931.20944)
Please contact us if you need assistance.