Microsoft ignored months-old security bug in Outlook that allowed email spoofing

Alfonso Maruccia

Posts: 2,561   +951
Staff
Facepalm: While Microsoft focuses on fixing its weak security practices, critical bugs in its many services and products keep popping up. A researcher discovered a dangerous flaw in Outlook months ago, but Microsoft waited until now to respond and attempt to fix it.

SolidLab security researcher Vsevolod Kokorin discovered a vulnerability that allowed him to impersonate any Outlook account, sending potentially malicious emails from apparently legitimate users. Kokorin demonstrated the critical bug by spoofing Microsoft's security team, but Redmond's response wasn't exactly what he expected.

SolidLab discovered the flaw months ago and alerted Microsoft immediately. The company said it couldn't reproduce the issue, so Kokorin sent a video showing his successful exploitation with a "full" proof-of-concept (PoC).

The impersonation PoC exploit only works when sending mails to an Outlook account, which is still one of the most popular email services with 400 million users worldwide. Microsoft could not reproduce the bug, so the company closed the issue.

Kokorin vented his frustration by ranting on X and privately sharing the technical details of the bug with TechCrunch. He did not expect a mob to form that was angry at him. Many "misunderstood" his intentions and accused him of leveraging public attention for monetary gain. Kokorin said all he wanted was to force giant corporations like Microsoft to stop ignoring researchers and be less dismissive when alerted to potentially damaging bugs in their software.

"I did not expect my post to get such a reaction. Honestly, I just wanted to share my frustration because this situation made me sad," Kokorin told TechCrunch. "Many people misunderstood me and think that I want money or something like that. In reality, I just want companies not to ignore researchers and to be more friendly when you try to help them."

Surprisingly, the faux-X-rage about the Outlook bug did what Kokorin had hoped. Microsoft reopened the issue. Redmond likely noticed Kokorin's post and revisited the reports he submitted. The Outlook email bug is still open at the time of writing.

Microsoft CEO Satya Nadella recently expressed dissatisfaction regarding the company's practices in dealing with security bugs. Nadella sent an internal memo explaining that Microsoft should now prioritize security above everything else in a company-wide push involving all teams and projects. The US Cyber Safety Review Board also labeled Microsoft's practices as "inadequate" after investigating major security incidents involving Windows and other products.

Permalink to story:

 
Nadella should be thrown in prison. He's personally responsible for this farce and has labelled himself the new security chief. Lock him up.
 
I bet that Microsoft's hidden motto is "that will do".
They really don't care about quality, or their customers.
 
There will ALWAYS be security holes... I wish they'd stop pushing their "new" Outlook (which is basically a glorified web client) and work on supporting their paid Outlook app which still doesn't support many web-based emails - I want to check my @rogers.com email AND be able to archive to .PST at the same time please!
 
There will ALWAYS be security holes... I wish they'd stop pushing their "new" Outlook (which is basically a glorified web client) and work on supporting their paid Outlook app which still doesn't support many web-based emails - I want to check my @rogers.com email AND be able to archive to .PST at the same time please!
The paid outlook app is still a farce though. Even with an outlook account it's the most unstable piece of cr@p that exists, lagging and not responding at the most random times.
 
Well, as far as I'm concerned he followed responsible disclosure. He let Microsoft know; and they made it clear they were not going to do anything about it. At that point he's free to publicly disclose (and that's better anyway, so the public knows there's a huge security hole rather than having hackers use it privately.)
 
Microsoft doesn't care about anything anymore, unless it's money. Security? Who cares. Performance? Who cares. Privacy? Who cares. User choice (customization/accessibility)? Who cares.

I wonder where the company would be right now if Gates, or even Ballmer, was still steering the ship...
 
MS has for years put profits over security, but it seems this year every few weeks there is something else like this.
Security is certainly not high on the list of MS priorities.

Personally I think they have lost the plot. Good third party Anti Malware, and increasingly a decent third party interface for MS pathetic firewall, which they change at will (often too) I consider essential as long as I use Windows.

Impossible to trust. They just leave a sour taste in the mouth, but that bit is just my feeling.
 
Back