Microsoft has some great tips to help you spot Outlook security flaws

Microsoft has released a new guide to help users determine whether or not a threat actor tried to steal sensitive data by exploiting a recently patched zero-day vulnerability found in its Outlook email (opens in new tab) client.

The vulnerability is tracked as CVE-2023-23397, and it’s described as a privilege escalation security flaw on Windows, allowing threat actors to steal NTLM hashes without the victim interacting on their side of the endpoint. The attack is called NTLM-relay zero-click attack.

Source