Microsoft Outlook stops displaying inline SVG images used in attacks

Microsoft has implemented a security enhancement in Outlook by disabling the display of inline SVG images. This change aims to mitigate attacks that exploit SVG images to deliver malicious payloads or execute harmful scripts within emails. SVG (Scalable Vector Graphics) images have been increasingly used by threat actors as a vector for embedding malicious code, leading to potential compromises of user systems when viewed in vulnerable email clients. The update affects how Outlook handles SVG content, preventing the automatic rendering of these images inline, thereby reducing the attack surface for phishing campaigns and malware distribution. This move is part of Microsoft's broader effort to strengthen email security and protect users from sophisticated cyber threats. Security researchers have noted that attackers often leverage SVG files to bypass traditional email security filters, embedding scripts or links that can trigger further exploitation once the email is opened. By blocking inline SVG rendering, Outlook limits the ability of attackers to use this technique effectively. This change underscores the importance of continuous security improvements in widely used software to counter evolving cyberattack methods. Organizations and users are encouraged to keep their software updated and remain vigilant against phishing and other email-based threats. Overall, Microsoft's decision to stop displaying inline SVG images in Outlook represents a proactive step in enhancing email security, protecting millions of users from potential SVG-based attacks and contributing to a safer digital communication environment.

This Cyber News was published on www.bleepingcomputer.com. Publication date: Thu, 02 Oct 2025 18:15:05 +0000


Cyber News related to Microsoft Outlook stops displaying inline SVG images used in attacks

Microsoft Outlook stops displaying inline SVG images used in attacks - Microsoft has implemented a security enhancement in Outlook by disabling the display of inline SVG images. This change aims to mitigate attacks that exploit SVG images to deliver malicious payloads or execute harmful scripts within emails. SVG ...
3 months ago Bleepingcomputer.com
CVE-2024-26805 - In the Linux kernel, the following vulnerability has been resolved: netlink: Fix kernel-infoleak-after-free in __skb_datagram_iter syzbot reported the following uninit-value access issue [1]: netlink_to_full_skb() creates a new `skb` and puts the ...
1 year ago Tenable.com
CVE-2024-26633 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2023-53109 - In the Linux kernel, the following vulnerability has been resolved: ...
8 months ago
CVE-2024-35893 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
What Is Patch Management? - Containers are created using a container image, and a container image is created using a Dockerfile/Containerfile that includes instructions for building an image. Considering the patch management and vulnerability management for containers, let's ...
1 year ago Feeds.dzone.com
CVE-2024-26857 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2021-47341 - In the Linux kernel, the following vulnerability has been resolved: KVM: mmio: Fix use-after-free Read in kvm_vm_ioctl_unregister_coalesced_mmio BUG: KASAN: use-after-free in kvm_vm_ioctl_unregister_coalesced_mmio+0x7c/0x1ec ...
1 year ago Tenable.com
CVE-2024-42076 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2023-53863 - In the Linux kernel, the following vulnerability has been resolved: ...
1 month ago
CVE-2025-40309 - In the Linux kernel, the following vulnerability has been resolved: ...
1 month ago
CVE-2021-47597 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2024-42311 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2023-54265 - In the Linux kernel, the following vulnerability has been resolved: ...
3 weeks ago
CVE-2024-26625 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2024-26882 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2024-35888 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2025-21707 - In the Linux kernel, the following vulnerability has been resolved: ...
10 months ago
CVE-2025-38323 - In the Linux kernel, the following vulnerability has been resolved: ...
6 months ago
CVE-2025-38578 - In the Linux kernel, the following vulnerability has been resolved: ...
5 months ago
Microsoft says button to restore classic Outlook is broken - Since the beginning of the year, it has addressed other Outlook issues, including one that causes classic Outlook to crash when writing, replying to, or forwarding an email, and another one that led to Classic Outlook and Microsoft 365 applications ...
10 months ago Bleepingcomputer.com
CVE-2023-52577 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2024-26641 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2024-47685 - In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put() syzbot reported that nf_reject_ip6_tcphdr_put() was possibly sending garbage on the four reserved tcp bits (th->res1) Use ...
1 year ago Tenable.com
CVE-2024-44946 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago