Microsoft Outlook email users who use the S/MIME encryption standard are not protected from the content of their emails by an application error.
The issue occurs because Outlook sends emails in both encrypted and unencrypted formats. So an attacker who is able to intercept the email account's traffic can read the content of these messages.
The bug is not a general one, but only manifests itself when the following conditions are met:
- Only emails encrypted with the S/MIME, but not PGP/GPG.
- Leakage of encrypted emails only occurs for emails that are “sent” using Outlook and not received by Outlook.
- The leak only occurs for Outlook emails sent in plain text. Outlook's default setting is to use HTML formatting.
- Leakage also occurs when users try to encrypt replies to emails. Outlook automatically changes the default HTML formatting to plain text when you reply to such messages.
- The leak occurs continuously if the user uses Outlook with an SMTP server.
- The leak only occurs on hop servers for Outlook clients using Microsoft Exchange infrastructure. This limits the leakage of encrypted email messages within a corporate network.
- There is also a leak in the recipient's email client. Because email clients display message previews, an attacker can view the contents of the encrypted message even if they do not have access to the recipient's private encryption key.
Encryption leakage, although limited by the above scenarios, is a sensitive issue. Companies and individuals alike use encryption to secure sensitive information exchanged via email.
SEC Consult researchers discovered the leak of encrypted Outlook emails by accident.
The researchers said they contacted Microsoft about the issue, and the company released a fix for the flaw — codenamed CVE-2017-11776— on Tuesday, October 10, 2017.
Microsoft did not disclose which versions of Outlook were affected by this issue.
Currently, companies and individuals who meet the above scenarios are vulnerable to CVE-2017-11776 and should update Outlook immediately.
