Office 365: OME encryption method bypassable

VG word pixels

Fix impossible?

Microsoft Office 365 is facing a serious security problem: security researchers want to have cracked the OME encryption.

news

VG word pixels

Woman uses a laptop with the Microsoft Office logo on it.
Office 365 has a new vulnerability.
© Adobe Stock: PhotoGranary

Microsoft Office 365 is the best-known suite of its kind and is used as the market leader by millions of customers. The demands on the encryption standard used, which in the case of e-mail traffic is based on the OME (Office Message Encryption) process, are correspondingly high. As researchers from the security company “WithSecure“, but this is based on a fatal error that may lead to attacks and may not be able to be fixed.

Specifically, the block cipher ECB (Electronic Codebook) is targeted, which is provided with detailed explanations of the structure of sent messages. If an attacker gains access to a large number of emails, they could infer further information about the key based on the position and structure of the pattern used.

If only individual messages are hijacked, the probability of a compromise is still low – however, the statistical probability increases if, for example, the entire mail archive gets into the hands of the attacker, since cracking the key can be used to reconstruct the plain text of the messages, among other things , although this involves a great deal of effort.

Closing the security gap seems to be even more problematic than the vulnerability itself. Since the vulnerability of OME lies in the basic architecture, a classic update with a security bug fix cannot do anything here – the vulnerability will probably remain for the time being. Microsoft itself has not yet commented on this.

Corona virus: home office

Open Source Tools

Securing the home network in the home office: This is how it works

Security gaps in routers or Windows tear ingress points into your home network. With the right tips and tools, you can prevent most of the dangers…

How to optimize the WiFi signal in the office

DocX, ODT, ODF and more

How do I open files from OpenOffice & LibreOffice in…

On the one hand Microsoft Word, on the other hand LibreOffice Writer. We’ll show you how to open ODT, ODF and more format files in Word…

10/17/2022 from
Yusuf Hatic

Continue to home page

more on the subject

microsoft 365 office design preview vision

New user interface

Microsoft 365: Video shows preview of new Office design

Less UI, focus on content: Microsoft announces major changes for the Office interface. A video shows the new vision for Microsoft 365.

Microsoft Office Tips

When is the patch coming?

Office vulnerability: “Follina” vulnerability…

The “Follina” vulnerability has been confirmed by Microsoft and allows attacks on PCs via Office files. So far there is no patch.

CPU, RAM, Malware & Co.: Fix PC problems - this is how it works

knot weed

Microsoft caught Austrian spyware group

Microsoft has unmasked an Austrian provider of spyware that previously posed as a security company. The group is for the Subzero…

emotet trojan protection

company at risk

Microsoft: mail services in the focus of phishing attacks

A phishing campaign uses targeted attacks against companies that use Microsoft mail services. Outlook users must take this into account.

Microsoft

Token danger

Vulnerability discovered in Microsoft Teams

Security experts have discovered a vulnerability in Microsoft Teams. Attackers can take advantage of tokens that are stored locally.

Reference-www.pc-magazin.de