Skip to main content

Microsoft Outlook Preview Vulnerability

A vulnerability in the way the Microsoft Outlook email application handles attachment previews could allow an attacker to execute malicious code without interacting with the user.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability in the way the Microsoft Outlook email application handles attachment previews could allow an attacker to execute malicious code without interacting with the user.

Threat details

The vulnerability lies in the method used by Windows Object Linking and Embedding (OLE) automation function and how it handles Rich Text Files (.RTF). Emails sent in RTF format and previewed in Outlook will have their content fetched automatically by OLE, meaning any malicious attachments would be executed without the user opening them.


Threat updates

Date Update
2 May 2018

This vulnerability can also be exploited in the same manner using PDF (.pdf) files.


Remediation steps

Type Step
  • This vulnerability was patched in Aprils updates, please see our article here.
  • Block NT LAN Manager (NTLM) and Single Sign-On authentication.

Last edited: 17 February 2020 12:48 pm