{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "cve": {
    "id": "CVE-2023-23397",
    "description": "Microsoft Outlook elevation of privilege. A crafted appointment with a UNC path in the reminder sound property forces Outlook to authenticate to an attacker-controlled SMB server, leaking the Net-NTLMv2 hash with zero user interaction — the message does not need to be opened.",
    "cvss": 9.8,
    "publishedDate": "2023-03-14",
    "product": "Microsoft Outlook",
    "vendor": "Microsoft",
    "inKev": true,
    "kevDateAdded": "2023-03-14",
    "severity": "critical",
    "nvd": "https://nvd.nist.gov/vuln/detail/CVE-2023-23397",
    "exploitedBy": [
      {
        "slug": "apt28",
        "name": "APT28",
        "country": "Russia",
        "countryCode": "RU",
        "firstExploited": "2022-04-01",
        "zeroDay": true,
        "usage": "Exploited as a zero-day for roughly eleven months before patch against government, military, energy, and transport targets in Europe. A crafted calendar invite forced Outlook to authenticate to attacker SMB infrastructure, leaking Net-NTLMv2 hashes with no user interaction at all.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "url": "https://www.microsoft.com/en-us/security/blog/2023/03/24/guidance-for-investigating-attacks-using-cve-2023-23397/"
        },
        "profile": "/apt/apt28/"
      }
    ]
  }
}