Background
On March 14, 2023, Microsoft disclosed a vulnerability in Outlook for Windows that allows credential theft. Microsoft has released a patch for Outlook to address this vulnerability.There are no user-level workarounds to mitigate this vulnerability so users should update Outlook as soon as possible.
Impact
Malicious actors can send specially crafted emails that expose user credentials to the attacker. These credentials can then be used by the attacker to authenticate as the victim. This vulnerability requires no user interaction and will execute upon receipt in the Outlook client BEFORE being opened or seen in the preview pane.
Platforms Affected
All supported versions of Microsoft Outlook for Windows are affected. Other versions of Microsoft Outlook such as Android, iOS, Mac, as well as Outlook on the web and other M365 services
Local Observations
The UISO has not observed local attacks exploiting this vulnerability.
UISO recommendations
The UISO recommends applying the patch provided by Microsoft as soon as possible, regardless of where your mail is hosted. It can be applied via Windows Update or finding your appropriate version of Windows on the update guide.