Advisory Details

February 18th, 2022

Microsoft Outlook for Mac Hyperlink UI Misrepresentation Vulnerability

ZDI-22-381
ZDI-CAN-14886

CVE ID
CVSS SCORE 6.5, AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
AFFECTED VENDORS Microsoft
AFFECTED PRODUCTS Outlook for Mac
VULNERABILITY DETAILS

This vulnerability allows remote attackers to disguise the target of hyperlinks on affected installations of Microsoft Outlook for Mac. User interaction is required to exploit this vulnerability in that the target must view a malicious email.

The specific flaw exists within the rendering of HTML in email. By supplying crafted HTML, an attacker can cause Outlook to incorrectly display the target of a hyperlink upon mouse hover. An attacker can leverage this vulnerability to deceive an email recipient regarding the trustworthiness of a link.

ADDITIONAL DETAILS

Fixed in version 16.53 and forward.


DISCLOSURE TIMELINE
  • 2021-08-05 - Vulnerability reported to vendor
  • 2022-02-18 - Coordinated public release of advisory
CREDIT Simon Zuckerbraun - Trend Micro Zero Day Initiative
BACK TO ADVISORIES