Also, if organisations need to maintain external channels of communication, they can define specific domains in an allow-list, to lower the risk of exploitation. However, the tech giant has mentioned that the security flaw “did not meet the bar for immediate servicing,” as per the report.
Microsoft’s response to the claim This vulnerability was reported to Microsoft, and the company validated that the flaw is legitimate. This also increases the chances of the target downloading the file into their systems. Moreover, if any attacker registers a domain similar to the target organisations on Microsoft 365, their messages could appear as if they are coming from someone within the organisation and not an external tenant.