Security News > 2022 > October > FYI: Microsoft Office 365 Message Encryption relies on insecure block cipher

Microsoft Office 365 Message Encryption claims to offer a way "To send and receive encrypted email messages between people inside and outside your organization."
Office 365 Message Encryption relies on a strong cipher, AES, but WithSecure says that's irrelevant because ECB is weak and vulnerable to cryptanalysis regardless of the cipher used.
Microsoft leaves the Office, rebrands everything as 365.
Microsoft in April introduced a data governance system called Microsoft Purview.
Office 365 Message Encryption is now considered a legacy system.
"Since Microsoft has no plans to fix this vulnerability the only mitigation is to avoid using Microsoft Office 365 Message Encryption," the lab concludes.
News URL
Related news
- Fake Microsoft Office add-in tools push malware via SourceForge (source)
- Microsoft blocks ActiveX by default in Microsoft 365, Office 2024 (source)
- Malicious Adobe, DocuSign OAuth apps target Microsoft 365 accounts (source)
- Hidden Threats: How Microsoft 365 Backups Store Risks for Future Attacks (source)
- Microsoft: New Windows scheduled task will launch Office apps faster (source)
- Microsoft: Licensing issue blocks Microsoft 365 Family for some users (source)
- Microsoft releases emergency update to fix Office 2016 crashes (source)
- Tycoon2FA phishing kit targets Microsoft 365 with new tricks (source)
- ActiveX blocked by default in Microsoft 365 because remote code execution is bad, OK? (source)
- Microsoft: Office 2016 and Office 2019 reach end of support in October (source)