CVE-2022-23280: Microsoft Outlook for Mac Security Feature Bypass Vulnerability

Overview

Severity
Medium (CVSS 5.3)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
Category
Security Feature Bypass
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2022-Feb
Released
2022-02-08
Last Updated
2022-02-09
EPSS Score
3.19% (percentile: 87.0%)

FAQ

What kind of security feature could be bypassed by successfully exploiting this vulnerability? The attacker would be able to bypass the protection in Outlook that prevents an image from being shown automatically in an email. Depending on the user's settings, the user would normally need to choose to download images for display. If an attacker successfully exploited this vulnerability it could expose the target's IP information. How do I get the update for Outlook for Mac? Tap the Settings Icon Tap the iTunes & App Store Turn on AUTOMATIC DOWNLOADS for Apps Alternatively Tap the App Store Icon Scroll down to find Microsoft Outlook Tap the Update button If the preview pane is an attack vector, why is the severity for this vulnerability Important and not Critical? Even though the preview pane is an attack vector, the attacker cannot achieve remote code execution if they successfully exploit the vulnerability, but can only gain information from the victim. Is the Preview Pane an attack vector for this vulnerability? Yes, the Preview Pane is an attack vector.

Affected Products (1)

Microsoft Office

  • Microsoft Outlook 2016 for Mac

Acknowledgments

<a href="https://twitter.com/r0ns3n">Ronnie Salomonsen</a> with <a href="https://www.mandiant.com/">Mandiant</a>

Revision History

  • 2022-02-08: Information published.
  • 2022-02-09: Updated acknowledgment. This is an informational change only.