Outlook forwarding rule can bypass corporate blocks, say researchers

By
Follow google news

Persistent post-exploitation vulnerability.

Microsoft Outlook Desktop has an unpatched vulnerability that would allow a successful attacker to configure a persistent mail forwarder.

Outlook forwarding rule can bypass corporate blocks, say researchers

Trustwave reported the vulnerability to Microsoft, and said the vendor response is that there’s no fix and no timeline for a fix.

“There is an exploitation method that can automatically forward emails CC’d to external addresses via an Outlook Desktop rule, even when this action is prevented on the corporate Exchange server," Trustwave said.

An attacker would need backdoor access to their victim, so they can access Outlook Desktop and create a rule adding the exfiltration address to the Outlook contacts list, and create the rule copying outgoing messages to that address.

The same vulnerability could be used by insiders to pass information to others.

“It also permits legitimate non-breached account owners to bypass any Exchange rules prohibiting emails from being auto forwarded to external addresses”, Trustwave said.

“If the attack gets discovered and the system cleaned up from the back door the attacker will still receive confidential emails to his inbox unless the IR team knows to look at the CC rules”, Trustwave said.

“This issue cannot be solved by any existing measures, including by configuring the Mail Flow rules settings in Exchange."

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

Attacker embeds Claude Code in mass credential harvesting op

Attacker embeds Claude Code in mass credential harvesting op

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

Log In

  |  Forgot your password?