In a concerning development for Microsoft and its users, a security researcher has uncovered a significant vulnerability that allows malicious actors to impersonate Microsoft corporate emails. This flaw, which remains unpatched as of June 24, 2024, poses a severe threat to the approximately 400 million Outlook users worldwide.
Microsoft corporate emails Outlook email bug
The bug was first brought to light by Vsevolod Kokorin, a security researcher also known as Slonser. Kokorin initially reported the vulnerability to Microsoft, but the company dismissed his findings, stating they were unable to reproduce the issue. Frustrated by the lack of response, Kokorin took to X (formerly Twitter) to publicize the bug, careful not to disclose technical details that could be exploited.
This security flaw is particularly dangerous as it allows attackers to send emails that appear to come from legitimate Microsoft corporate accounts, such as security@microsoft.com. The vulnerability specifically affects Outlook accounts, which comprise a substantial user base of around 400 million individuals.
The potential for abuse is significant:
- Phishing Attacks: Malicious actors could craft highly convincing phishing emails, leveraging the perceived legitimacy of Microsoft’s corporate accounts.
- Data theft: Users might be more inclined to share sensitive information or click on malicious links, believing the emails to be from trusted Microsoft sources.
- Malware distribution: The bug could be exploited to distribute malware under the guise of official Microsoft communications.
Microsoft’s response
Initially, Microsoft was unable to reproduce the issue and dismissed Kokorin’s report. However, following the public disclosure, there are indications that the company may be taking the matter more seriously. Kokorin reported that Microsoft has reopened one of his previously submitted reports, suggesting they may now be investigating the issue.
Recommendations for Outlook users
While awaiting an official patch from Microsoft, security experts recommend the following precautions for Outlook users:
- Exercise extreme caution when opening emails that appear to be from Microsoft corporate accounts.
- Avoid clicking on links or downloading attachments from unexpected emails, even if they seem to be from Microsoft.
- Implement additional security measures such as robust antivirus software and email filtering systems.
- Stay informed about official Microsoft communications regarding this vulnerability and any forthcoming patches.
This incident raises questions about Microsoft’s vulnerability reporting and response processes. It comes at a particularly sensitive time for the company, which recently faced criticism over security lapses that allowed Chinese state-sponsored actors to access U.S. government emails.

The discovery of this Outlook email bug underscores the ongoing challenges in maintaining email security and the constant need for vigilance in the face of evolving cyber threats. As Microsoft works to address this vulnerability, it serves as a reminder of the critical importance of prompt and thorough responses to security researchers’ findings.
About The Author
Discover more from Microsoft News Now
Subscribe to get the latest posts sent to your email.

