Vulnerability in Microsoft Outlook makes users believe in phishing emails
A new vulnerability has just been discovered by a security researcher on the Microsoft Outlook platform. This vulnerability makes users believe in phishing emails.
The cause of the problem was that Outlook's Address Book displayed the user's contact information including information from the Internationalized Domain Name (IDN). Meanwhile, IDN consists of letters from different scripts such as Cyrillic with face shapes similar to those in the Latin alphabet.
Therefore, bad guys can easily take advantage of this vulnerability to impersonate individuals from reputable organizations. Users will be easily fooled when looking at contact information with fake domains that look like the real thing.
This vulnerability was discovered by a security researcher nicknamed Dobby1Kenobi. He reported it to Microsoft and Microsoft confirmed the issue but refused to patch the vulnerability at the time.
Microsoft believes that Outlook users should not trust the sender's identity without a digital signature. Although spoofing issues can occur, Microsoft decided not to patch to avoid false positives.
However, recently Microsoft finally released the necessary patch. As reported by Windows Central, in Outlook 16.0.14228.20216, Microsoft fixed the issue reported by Dobby1Kenobi. Therefore, to be on the safe side, you should update your Outlook to the latest version.
In addition, to avoid being scammed, always pay attention to the identity of the sender. In case of an important transaction, in addition to online identity verification, you need to combine direct contact to ensure safety.
You should read it
- Microsoft Outlook RCE Vulnerability Can Sell For $400,000
- Leaked series of screenshots of Microsoft's new 'One Outlook' email client for Windows 11
- 7 Outlook.com tricks you may not know yet
- Microsoft Outlook acceleration tips
- Error cannot open Outlook, this is a fix
- How to use Microsoft Outlook for project management
- Microsoft fixes a serious security hole
- How to use the Outlook.com Beta version
May be interested
- Microsoft admits hackers may have read Outlook email and warned users to change their passwordshackers may have gained access to some user's outlook.com accounts and viewed email addresses, folder names, and email topics.
- Instructions for configuring Gmail on Outlookoutlook makes it easy for you to manage your gmail emails. send and receive emails quickly without accessing gmail's webmail. use microsoft office directly from microsoft office.
- Microsoft Outlook Has a 'Severe' Vulnerability That Could Easily Spread Malwaremicrosoft has just officially warned users about the existence of a vulnerability that could allow hackers to easily spread malware through the outlook email application.
- Microsoft wants users to switch to the new Outlook before August, or receiving emails will be interruptedthe new outlook for windows app is essentially built on the outlook.com web app.
- Instructions for pinning emails in Outlookwith the outlook application, pinning emails on the computer or phone is also extremely simple and easy to do. when you pin emails on outlook, you can unpin emails whenever you need.
- Microsoft Outlook users can't view and compose emails, see these fixesthe microsoft outlook 2104 build 13929.20372 update released on may 11 left many desktop users unable to view and compose emails. in this article, tipsmake.com will help you fix this problem!
- How to save Microsoft Outlook emails as PDF filessometimes in some cases, you may want to save your microsoft outlook emails as pdf files for offline use when needed. this article will show you how to do that in the web and desktop versions of outlook.
- Warning: Phishing attacks targeting Microsoft Teams show signs of sharp increasemicrosoft teams is reluctant to be the new target that online scammers are targeting.
- [Infographic] How to recognize and prevent Phishing attacksthere are dozens or even hundreds of emails sent to your inbox every day. so how do i know they are not phishing attack emails?
- Apple shows users how to distinguish phishing emails from the App Storeapple has just published a guide on how to distinguish fraudulent emails.