Outlook may have allowed unencrypted connections for decades, report claims — Fedora and Dovecot upgrade reveal protocol downgrade issue present since at least 2007
Source
Published
TL;DR
AI GeneratedAn IT blogger discovered a significant security vulnerability in Microsoft Outlook where SSL/TLS connections were being downgraded to unencrypted plaintext without user notification. This issue affects Outlook versions from 2007 to 2016, potentially even later versions. The problem was uncovered during a mail server upgrade from Fedora 42 to Fedora Server 43, causing errors for users with the "Use TLS/SSL" checkbox enabled in Outlook. The issue stems from a protocol downgrade triggered by selecting port 110 and using the POP3 protocol, leading to unencrypted email retrieval for over a decade. The recent Dovecot upgrade in Fedora Server 43 revealed this behavior, emphasizing the importance of ensuring encrypted connections for email security.