Microsoft has issued a fix for a “high severity” password reset vulnerability that was found in its Hotmail service.
The exploit allowed an attacker to hijack email accounts by using a Firefox add-on called Tamper Data, which intercepts outgoing HTTP requests and allows them to modify the data, thereby enabling them to reset the password.
It is thought that an as-yet unspecified number of accounts had been compromised, possibly by hackers based in Morocco.
Microsoft’s Hotmail team first picked up on the issue after it was referred to them by Benjamin Kunz Mejri, CEO and founder of Vulnerability Lab. A temporary fix was issued on 20 April before a patch resolved the problem.
“Remote attackers now get redirected to an exception page when they try to manipulate the session to reset passwords,” Mejri told Softpedia. “The vulnerability has been located, we notified them and the public attacks have been prevented by MSRC. We informed Microsoft regarding the vulnerability with detailed information.”
How well do you know Internet security? Try our quiz and find out!
With China tariff set at 145 percent, Amazon CEO admits third party sellers may pass…
Hundreds of staff within the Android, Chrome and Pixel teams at Alphabet's Google are reportedly…
After weeks of tariff chaos, China hits back at Donald Trump and raises tariffs on…
Executive at Chinese owned Swedish EV maker Polestar admits targetting fed up Tesla owners with…
Escalation of feud between Sam Altman and Elon Musk, after OpenAI confirms it is now…
Report from International Energy Agency (IEA) warns AI is set to drive surging electricity demand…