By Exploiting This Office 365 Flaw, Attackers Can Send You Malicious Emails

Every windows user is also using Office 365 to maintain his business records and daily work. A major security vulnerability in Office 365 has been discovered by a Turkish security researcher, which is allowing attackers to send spoofed malicious emails from a fake “Microsoft.com” address. The name of this Turkish security researcher is “Utku Sen”. He is a cyber-security enthusiast and giving his best to protect the cyberspace from hackers. Utku Sen is known for his “Hidden Tear” named ransomware, which he had released for educational purposes.
What is the Exact Security Issue?
Utku said that he was testing spam filters of various email platform including Gmail, Outlook 365 and Yandex. He was using SEES (Social Engineering Email Sender) tool to conduct these tests. Utku was sending phishing emails from SEES tool and he noticed that Yandex was showing some of them as valid emails. Yandex was performing a DKIM (DomainKeys Identified Mail) verification process and after that, it was marking those phishing emails with a green signal. This green signal has been used by Yandex email filters to identify legit emails.
Confused? Let Us Explain It.
Actually, Utku was using a spoofed “Microsoft.com” domain based email address to send those phishing emails. Email filters of Yandex were marking them as legit emails due to the use of “Microsoft.com” domain. These emails were forwarded by Utku through Outlook 365 to Yandex. He performed the same tests on Gmail also. Utku sent some phishing emails from spoofed “microsoft.com” outlook account to a Gmail account and it was also marking those malicious emails as legit emails. Then he used some other spoofed domain names instead of “Microsoft.com” and the emails were going directly into spam folders.
Utku was also not understanding this issue. Then a “ptmb” named Reddit user explained the whole security issue. In actual, Outlook was signing all the redirected messages with its own DKIM keys. When spam filters of Outlook, Yandex and Gmail were verifying DKIM keys of phishing emails, they were marking it as legit because all the DKIM keys were legit outlook DKIM keys. Outlook was blindly signing all those emails which contain a fake Microsoft.com type saying in it’s from field. It means user will get an email from a redirector instead of a sender.
Update Your Office 365 ASAP
After discovering this major security issue, Utku immediately reported it to Microsoft. After testing, Microsoft found it right and they released an update in last week of October to fix it. If you are using an old version of Office 365, then update is as soon as possible. Some phishing cases have been noticed by security experts related to this vulnerability.
Other Hot Hacking News: