Microsoft Office – High Severity Vulnerability

Secure password entered on website Zero Trust

Earlier this month Microsoft announced there was a High Severity vulnerability affecting Microsoft Office products. At the time, we contacted all of our contracted support customers to inform of the vulnerability and we rapidly deployed patches to workstations and servers to protect against the vulnerability.

The ‘Microsoft Outlook Elevation of Privilege Vulnerability’  is a critical security flaw that affects all supported versions of Microsoft Outlook for Windows. It allows an attacker to steal the user’s credentials by sending a specially crafted email that triggers a connection to an external server controlled by the attacker. The attack was particularly nasty because the vulnerability can be exploited without any user interaction, even before the email is viewed in the preview pane. The attacker can then use the stolen credentials to authenticate with other services and gain access to the user’s network and data.

Microsoft released a security update to address this vulnerability, and has advised users to apply the update as soon as possible. Microsoft has also reported that this vulnerability has been exploited in limited, targeted attacks. Organisations should ensure employees are aware of the vulnerability and that they need to install these security patches available for Microsoft Office.  

Users can check their Outlook version and update status by following the instructions here. Alternatively there is a guide from Microsoft which explains how to update your versions of Office.  We strongly recommend that you share this with your employees and ask them to apply the updates and restart their workstations ASAP to reduce the threat of this vulnerability.

Moving forward, clients of new ‘Secure+’ cyber monitoring and response service will receive priority critical patching, as an inclusive part of the secure+ service. Please contact us if you would like more information.

Brochure: secure+ from ramsac

secure+ is a proactive cybersecurity monitoring service designed to hunt for signs of malicious activity or potential cyberbreach, ramsac then takes action to prevent damage from being done.

Related Posts

  • Most data issues are accidental. Here’s how to reduce the risk.

    Most data issues are accidental. Here’s how to reduce the risk.

    Cybersecurity

    Most data breaches aren’t caused by hackers, they’re caused by everyday behaviour. Discover how accidental risk builds in Microsoft 365 and what you can do to reduce it without [...]

    Read article

  • Why are charities increasingly being attacked by cyber criminals? 

    Why are charities increasingly being attacked by cyber criminals? 

    Cybersecurity

    More than a quarter of charities were reportedly the target of cybercrimes in the last year alone. But why are charities increasingly the victims of cyberattacks? Find out here… [...]

    Read article

  • When Cyber Insurance Matters: Lessons from Co‑op, M&S, Harrods and JLR

    When Cyber Insurance Matters: Lessons from Co‑op, M&S, Harrods and JLR

    Cybersecurity

    Cyberattacks hit Coop, M&S, Harrods and JLR in 2025. This blog explores real-world lessons from these breaches and why cyber insurance is now essential for every organisation. [...]

    Read article

  • Celebrating Cybersecurity Awareness Month 2025

    Celebrating Cybersecurity Awareness Month 2025

    Cybersecurity

    October is Cybersecurity awareness month, follow us on LinkedIn for tips on how you can protect your organisation against Cybercrime. [...]

    Read article

  • 13 Phishing attacks blocked in minutes, here’s how we did it.

    13 Phishing attacks blocked in minutes, here’s how we did it.

    Cybersecurity

    Phishing attacks are increasing, but last week our team stopped 13 in their tracks. Read how secure+ protected our clients, what caused the spike, and the key lessons your [...]

    Read article

  • How to set up a secure password policy in Microsoft 365

    How to set up a secure password policy in Microsoft 365

    CybersecurityMicrosoft 365

    Discover the benefits of a robust Microsoft 365 password policy and how to set it up. Strengthen your organisation's cybersecurity and protect your data today. [...]

    Read article

Quiz yourself

Are you more cyber savvy than an 11 year old?

11-14 year olds get asked these questions in school. Could you get these right?