Skip to Primary Navigation

Warning issued on Office 365 mail vulnerability, but Microsoft denies problem

Office 365 packaging
Photo: Getty Images

Use of ECB encryption shown to leave mail vulnerable in security firm’s tests.

Cybersecurity company WithSecure has published details of a vulnerability in Microsoft Office 365 Message encryption (OME), but Microsoft is so far refusing to acknowledge there is a risk that needs addressing.

WithSecure says the problem comes from Microsoft’s decision to use a block cypher confidentiality mode called Electronic Codebook (ECB). A

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience