Office 365 Email baseStriker Vulnerability
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
Using the base tag in HyperText Markup Language (HTML), it is possible to create a link in an email without including the full location that the link leads to. At the time of publication this method of linking is not analysed properly by Microsoft's security services, and so emails containing such links to malicious locations may not be blocked.
Attackers are currently exploiting this vulnerability in phishing attacks, but it is also possible to deliver links to malware and other malicious content.
Remediation steps
Last edited: 17 February 2020 12:51 pm