Microsoft Half-Patches Old Outlook Vulnerability

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Microsoft has published a patch for an Outlook vulnerability first reported in late 2016, but the patch has been deemed incomplete and additional workarounds are needed, according to the security researcher who discovered it.
Yesterday's April 2018 Patch Tuesday updates train included a fix for CVE-2018-0950, a vulnerability in Microsoft Outlook discovered by Will Dormann, a vulnerability analyst at the CERT Coordination Center (CERT/CC).

Outlook retrieves remote OLE content without prompting

According to Dormann, the main problem with CVE-2018-0950 is that Microsoft Outlook will automatically render the content of remote OLE objects embedded inside rich formatted emails without prompting the user, something that Microsoft does in other Office apps such as Word, Excel, and PowerPoint.

This leads to a slew of problems that come from automatically rendering OLE objects, a common attack vector for malware authors.

Dormann says that during his experiments he was able to exploit this Outlook OLE handling design decision to steal user account passwords (NTLM hashes, to be more precise) from Windows computers.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top