Summary:
Microsoft has released a solution for Outlook Desktop's blocking of attempts to open hyperlinks containing IP addresses or fully qualified domain names (FQDN) after installing the latest security updates. The company advises that Outlook prevents opening FQDN and IP address hyperlinks due to the release of protections for the Microsoft Outlook Security Feature Bypass Vulnerability. Outlook for Microsoft 365 users may experience silent failures, warnings that the location may be unsafe, or "Something unexpected went wrong with this URL" errors on affected systems. This problem only occurs when clicking on links in emails within Outlook Desktop that lead to an FQDN, IP address, or hostname path. the CVE-2023-33151 Outlook Spoofing Vulnerability and the CVE-2023-35311 Outlook Security Feature Bypass Vulnerability. Microsoft also offers a temporary fix for affected customers to enable all hyperlinks to function normally. However, the company warns that applying the workaround may increase the attack surface on affected systems. Microsoft advises users to ensure that the FQDN or IP address added to Trusted Sites is a valid URL path for their company or network.[/subscribe_to_unlock_form]
Summary:
Microsoft has released a solution for Outlook Desktop's blocking of attempts to open hyperlinks containing IP addresses or fully qualified domain names (FQDN) after installing the latest security updates. The company advises that Outlook prevents opening FQDN and IP address hyperlinks due to the release of protections for the Microsoft Outlook Security Feature Bypass Vulnerability. Outlook for Microsoft 365 users may experience silent failures, warnings that the location may be unsafe, or "Something unexpected went wrong with this URL" errors on affected systems. This problem only occurs when clicking on links in emails within Outlook Desktop that lead to an FQDN, IP address, or hostname path. the CVE-2023-33151 Outlook Spoofing Vulnerability and the CVE-2023-35311 Outlook Security Feature Bypass Vulnerability. Microsoft also offers a temporary fix for affected customers to enable all hyperlinks to function normally. However, the company warns that applying the workaround may increase the attack surface on affected systems. Microsoft advises users to ensure that the FQDN or IP address added to Trusted Sites is a valid URL path for their company or network.[emaillocker id="1283"]
Recommendations:
We strongly recommend you apply the security patch for the Outlook security feature bypass vulnerability and Outlook spoofing vulnerability.
References:
The following reports contain further technical details:
[/emaillocker]