A security researcher has uncovered a bug in Outlook that could allow anyone to impersonate Microsoft corporate email accounts, giving phishing attempts an air of legitimacy to trick unsuspecting targets. An urgent warning has been issued to Outlook's roughly 400 million users as the vulnerability remains unpatched.
Vsevolod Kokorin, a security researcher at SolidLab, first sounded the alarm about this email spoofing bug in a post on X (formerly Twitter) last week. He said he disclosed the issue to Microsoft, only for the company to dismiss his report after saying it couldn't reproduce his findings. Frustrated, Kokorin took to X to warn others while rightly refusing to provide the technical details needed to exploit the vulnerability.
As demonstrated in screenshots he shared, the bug lets anyone impersonate an official Microsoft corporate account when sending an email to another Outlook user. In an update, he said that Microsoft has acknowledged the issue, though a timeline for when it'll be patched remains unclear. He also told TechCrunch that Microsoft may have come across his tweet, as it has since reopened one of the reports he submitted several months ago. We've reached out to Microsoft for comment and will update this story once we hear back.
I want to share my recent case:> I found a vulnerability that allows sending a message from any user@domain> We cannot reproduce it > I send a video with the exploitation, a full PoC > We cannot reproduce itAt this point, I decided to stop the communication with Microsoft. pic.twitter.com/mJDoHTn9XvJune 14, 2024
How to protect yourself from new Outlook spoofing bug
Given that bad actors only need to email another Outlook account to exploit this bug, all 400 million Outlook users are at risk of phishing attempts from otherwise legitimate look Microsoft corporate accounts. While we don't know yet when it'll be patched, if you're an Outlook user, there are some precautions you can take in the meantime to stay safe.
Unfortunately, it mostly boils down to the age-old advice of staying vigilant. It's highly recommended that you stay alert to any messages you receive that appear to be from Microsoft. Kokorin has advised all Outlook users to be weary when opening new emails and to avoid clicking on strange links. Consider signing up for one of the best antivirus software solutions as well, many of which give you access to a VPN, password manager and other extras to help you stay safe online.