Flaw in Outlook for Android Allows for Data Theft
#1
Quote:A vulnerability recently addressed in Outlook for Android allows an attacker to steal information from the affected device.
 
The vulnerability, Microsoft reveals, resides in the manner in which Outlook for Android parses specifically crafted email messages. To exploit the flaw, an authenticated attacker needs to send a specially crafted email message to the victim.
 
“The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on the affected systems and run scripts in the security context of the current user,” the software giant explains in an advisory.
Tracked as CVE-2019-1105, the vulnerability was addressed last week “by correcting how Outlook for Android parses specially crafted email messages.”
 
F5 Networks security researcher Bryan Appleby, who reported the flaw to Microsoft, explains that the issue begins with the ability to embed an iframe into the email message.
JavaScript within the code would have no restrictions in Outlook on Android, being able to access cookies, tokens, and even some emails, which could also be sent back to a remote attacker.

SOURCE: https://www.securityweek.com/flaw-outloo...data-theft
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Actual Microsoft Azure AZ-900 Certificat...
Our AZ-900 exam dump...jacklim — 12:35
Microsoft Releases Windows 11 Insider Bu...
Microsoft has roll...harlan4096 — 09:22
WhatsApp Is Developing On-Device Scam De...
Meta is working on...harlan4096 — 09:21
Apple Announces macOS 27 Golden Gate, Dr...
Apple announced ma...harlan4096 — 07:38
AnyDesk 9.7.5 for Windows
Version 9.7.5 for ...harlan4096 — 06:00

[-]
Birthdays
Today's Birthdays
avatar (48)vadimTob
avatar (38)leannauu4
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (42)zacforat
avatar (47)NemrokReks
avatar (38)Barrackleve
avatar (40)Julioagopy
avatar (50)aolaupitt2558
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>