{"id":"CVE-2023-35636","title":"Microsoft Outlook Information Disclosure Vulnerability","summary":"Microsoft Outlook Information Disclosure Vulnerability","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","cwe":["CWE-200"],"vendor":"microsoft","product":"365_apps","affected":["365_apps","office = 2016","office = 2019","office_long_term_servicing_channel = 2021"],"published":"2023-12-12","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:24.453","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-35636","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35636","label":"secure@microsoft.com"},{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35636","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.17697,"epssPercentile":0.9709,"exploits":{"github":1,"githubRepos":["https://github.com/duy-31/CVE-2023-35636"],"checkedAt":"2026-10-08T23:17:21.760Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T23:16:47.354Z","slug":"CVE-2023-35636","body":"## Overview\n\nMicrosoft Outlook Information Disclosure Vulnerability\n\n## Affected\n\n- `365_apps`\n- `office = 2016`\n- `office = 2019`\n- `office_long_term_servicing_channel = 2021`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":51,"depthScoreParts":{"impact":35.8,"likelihood":3.5,"exploitation":12,"ransomware":0},"changes":[]}