U1 News
  • Home
  • World
  • U.S.
  • Business
  • Technology
  • Science
  • Entertainment
  • Sport
  • Health
Global News

Israel targets Hezbollah commander in Beirut strike after deadly Golan Heights attack

July 30, 2024

Taylor Swift speaks out after Southport mass stabbing at dance class

July 30, 2024

3 girls killed in stabbing at Taylor Swift-themed UK dance class. 7 people still critically wounded

July 30, 2024
Facebook Twitter Instagram
Trending
  • FDA approves first at-home HPV test to screen for cervical cancer
  • Brain stimulation technology improves Parkinson’s treatment for music conductor
  • Left-handedness linked to autism, schizophrenia in major neurological study
  • Heart health unexpectedly affected by shingles vaccine
  • Doctors remove spinal cancer through eye socket in revolutionary surgery
  • Laundry done at home by healthcare workers may spread superbugs, says new study
  • Longevity and organ function predicted in new ‘body clock’ tool
  • ‘Magic mushrooms’ may offer major relief for Parkinson’s patients, study shows
Sunday, May 11
U1 News
  • Home
  • World

    Israel targets Hezbollah commander in Beirut strike after deadly Golan Heights attack

    July 30, 2024

    Taylor Swift speaks out after Southport mass stabbing at dance class

    July 30, 2024

    3 girls killed in stabbing at Taylor Swift-themed UK dance class. 7 people still critically wounded

    July 30, 2024

    Kerala, India, hit by landslides, killing at least 99

    July 30, 2024

    Taylor Swift ‘in shock’ after horrific UK stabbing, as police say 3rd child dies

    July 30, 2024
  • U.S.

    Biden criticises ‘extreme’ Supreme Court in push for reform

    July 30, 2024

    FBI details shooter’s search history before Trump assassination attempt

    July 30, 2024

    Reps. Mike Kelly, Jason Crow to lead task force on Trump rally shooting

    July 29, 2024

    Biden to call for major Supreme Court reforms, including term limits, at Civil Rights Act event Monday

    July 29, 2024

    Sonya Massey’s death revives pain for Breonna Taylor, Floyd activists

    July 29, 2024
  • Business

    AMD stock jumps on earnings beat driven by AI chip sales

    July 30, 2024

    Amazon is responsible for dangerous products sold on its site, federal agency rules

    July 30, 2024

    Microsoft investigating new outages of services after global CrowdStrike chaos

    July 30, 2024

    S&P 500, Nasdaq Tumble as Chip Stocks Slide Ahead of Big Tech Earnings

    July 30, 2024

    American consumers feeling more confident in July as expectations of future improve

    July 30, 2024
  • Technology

    Apple says Safari protects your privacy. We fact checked those claims.

    July 30, 2024

    GameStop Dunks On Xbox 360 Store Closing And Gets Savaged

    July 30, 2024

    Logitech has an idea for a “forever mouse” that requires a subscription

    July 30, 2024

    Friend: a new digital companion for the AI age

    July 30, 2024

    London Sports Mod Community Devolves Into War

    July 30, 2024
  • Science

    NASA’s Lunar Gateway has a big visiting vehicles problem

    August 1, 2024

    Boeing’s Cursed ISS Mission May Finally Make It Back to Earth

    July 30, 2024

    Should you floss before or after you brush your teeth?

    July 30, 2024

    Ancient swimming sea bug ‘taco’ had mandibles, new fossils show

    July 30, 2024

    NASA’s DART asteroid impact mission revealed ages of twin space rock targets (images)

    July 30, 2024
  • Entertainment

    Richard Gadd Backs Netflix to Get ‘Baby Reindeer’ Lawsuit Dismissed

    July 30, 2024

    Batman: Caped Crusader review: a pulpy throwback to DC’s Golden Age

    July 30, 2024

    Channing Tatum Praises Ryan Reynolds For Taking Gamble On Gambit

    July 30, 2024

    ‘Star Wars Outlaws’ somehow made me fall in love with Star Wars again

    July 30, 2024

    Great Scott and O’Brien’s Pub find new life in Allston

    July 30, 2024
  • Sport

    How Snoop Dogg became a fixture of the Paris Olympics

    July 30, 2024

    Team USA’s Coco Gauff exits Olympics singles tournament with a third-round loss : NPR

    July 30, 2024

    French police investigating abuse targeting Olympic opening ceremony DJ over ‘Last Supper’ scene

    July 30, 2024

    French DJ Takes Legal Action

    July 30, 2024

    Why BYU’s Jimmer Fredette is at the 2024 Paris Olympics

    July 30, 2024
  • Health

    FDA approves first at-home HPV test to screen for cervical cancer

    May 10, 2025

    Brain stimulation technology improves Parkinson’s treatment for music conductor

    May 10, 2025

    Left-handedness linked to autism, schizophrenia in major neurological study

    May 10, 2025

    Heart health unexpectedly affected by shingles vaccine

    May 9, 2025

    Doctors remove spinal cancer through eye socket in revolutionary surgery

    May 9, 2025
U1 News
Home»Technology»Microsoft Issues Update Warning For All Outlook Users As ‘Dangerous’ New Threat Confirmed
Technology

Microsoft Issues Update Warning For All Outlook Users As ‘Dangerous’ New Threat Confirmed

u1news-staffBy u1news-staffJuly 12, 2024No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
0x0.jpg
Share
Facebook Twitter LinkedIn Pinterest Email

A sudden serious warning was issued to 500 million users

Photothek courtesy of Getty Images

This month, multiple Windows vulnerabilities (1,2) is on the list of vulnerabilities known to be exploited by the U.S. government. Now, a new report strongly suggests that 500 million Outlook users may be at the same level of risk from a “critical zero-click remote code execution (RCE) vulnerability affecting most Microsoft Outlook applications.”

Microsoft advice Although no exploitation has been detected to date, the company has warned that “the possibility of exploitation is increasing” and urged users to update their software. Morphisecwho reported the issue to Microsoft, went further: “Given the broader impact of this vulnerability, particularly its zero-click vector against trusted senders and its potential for broader impact, we have requested that Microsoft reassess the severity and classify it as ‘Critical’,” the company said.

ForbesMicrosoft Windows Deadline – You have 21 days to update your PCby

The researchers warn that the vulnerability “affects most Microsoft Outlook applications,” and there’s nothing in Microsoft’s own release to suggest otherwise. These are applications used by most large enterprises, not to mention the hundreds of millions of users of the Outlook email service. The researchers note that while this RCE is complex, “it may be possible to simplify the attack process by chaining this vulnerability with another.” The Outlook exploit threat targeting enterprises is clearly ransomware.

CVE-2024-3802 was fixed as part of Microsoft’s larger July security update, which Morphisec welcomed: “Given its zero-click nature (for trusted senders) and lack of authentication requirements, CVE-2024-38021 poses a serious risk.”

According to them, the threat spectrum includes “the[ing] “The vulnerability could be exploited to gain unauthorized access, execute arbitrary code, and cause severe damage without user interaction. The lack of authentication requirements makes it particularly dangerous as it could lead to widespread exploitation.”

The repeated reference to “trusted senders” in this alert is important: the vulnerability only poses a zero-click threat if the email is received from a trusted source. If the sender is unknown, the user must click to execute. That said, if the problem for an attacker is to forge an email from a trusted source, the bar is very low in today’s industrial-scale world of business email compromise.

ForbesWhatsApp ‘spyware’ warning – are your messages being read?by

“We deeply appreciate MorphiSec’s investigation and for responsibly reporting this under coordinated vulnerability disclosure. Customers who installed the update are already protected,” a Microsoft spokesperson said.

As is typical with these types of disclosures, few technical details are being released until most users have had a chance to patch their software, but those details will be made public shortly. Morphisec says it discovered the vulnerability through “extensive fuzzing and reverse engineering of the Microsoft Outlook codebase,” and will be sharing further findings with the security community at Def Con 32 in Las Vegas next month in a session intriguingly titled “Outlook Unleashes RCE Chaos.”

confirmed Dangerous issues Microsoft Microsoft Cyber ​​Security Microsoft warning microsoft windows patch tuesday outlook Outlook and Gmail Outlook Warning Threat update users warning Windows 10 Update Windows 10 warning g Windows 11 Upgrade Windows 11 warning
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
u1news-staff
u1news-staff
  • Website

Related Posts

Measles case confirmed in Midwestern state, first in over a decade

May 6, 2025

Teddi Mellencamp shares cancer battle update, doctors discuss risk

April 24, 2025

Measles outbreak confirmed in Michigan, along with 7 other US states

April 19, 2025

Measles case confirmed in Washington, DC

March 25, 2025
Add A Comment

Leave A Reply Cancel Reply

Latest Posts

FDA approves first at-home HPV test to screen for cervical cancer

May 10, 2025

Brain stimulation technology improves Parkinson’s treatment for music conductor

May 10, 2025

Left-handedness linked to autism, schizophrenia in major neurological study

May 10, 2025

Heart health unexpectedly affected by shingles vaccine

May 9, 2025
Unites States

Biden criticises ‘extreme’ Supreme Court in push for reform

July 30, 2024

FBI details shooter’s search history before Trump assassination attempt

July 30, 2024

Reps. Mike Kelly, Jason Crow to lead task force on Trump rally shooting

July 29, 2024

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

Copyright ©️ All rights reserved. | U1 News
  • Home
  • About Us
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.