Body Background
TrendAI™ Zero Day Initiative™ Logo

Microsoft Outlook for Mac Hyperlink UI Misrepresentation Vulnerability

February 18th, 2022

Vulnerability Details

This vulnerability allows remote attackers to disguise the target of hyperlinks on affected installations of Microsoft Outlook for Mac. User interaction is required to exploit this vulnerability in that the target must view a malicious email.

The specific flaw exists within the rendering of HTML in email. By supplying crafted HTML, an attacker can cause Outlook to incorrectly display the target of a hyperlink upon mouse hover. An attacker can leverage this vulnerability to deceive an email recipient regarding the trustworthiness of a link.

Additional Details

Fixed in version 16.53 and forward.


Disclosure Timeline

  • 2021-08-05 - Vulnerability reported to vendor
  • 2022-02-18 - Coordinated public release of advisory

Credit

Simon Zuckerbraun - Trend Micro Zero Day Initiative

Back to Advisories

Hero Background

Stand at the front line of proactive security

Trend ZDI connects the experts who discover, remediate, and defend.
Add your voice to the work that pushes attackers back.