Full Report
You didn't really want to be sending around .msix and .msixbundle files, did you?
Analysis Summary
# Vulnerability: Outlook Attachment Blocking for MSIX File Types
## CVE Details
* **CVE ID:** N/A (General security hardening/Policy update)
* **CVSS Score:** N/A
* **CWE:** CWE-434: Unrestricted Upload of File with Dangerous Type (Prevention)
## Affected Systems
* **Products:** Microsoft Outlook
* **Versions:** New Outlook for Windows, Outlook on the Web (OWA) via Exchange Online.
* **Configurations:** Default security configurations for Exchange Online mailbox policies.
## Vulnerability Description
Microsoft is expanding its "Blocked File Types" list in Outlook to include `.msix` and `.msixbundle` extensions. While not a specific software bug, these file formats are used for Windows application packaging. If a user executes a malicious MSIX package received via email, it can lead to full system compromise. This move follows a history of threat actors abusing the Windows App Installer architecture to bypass security controls and deliver malware directly to endpoints.
## Exploitation
* **Status:** Historically exploited in the wild (via `ms-appinstaller` abuse and social engineering).
* **Complexity:** Low (Requires user interaction to open the attachment).
* **Attack Vector:** Network (Email).
## Impact
* **Confidentiality:** High (Full system access if malware is installed).
* **Integrity:** High (Unauthorized software installation and system modification).
* **Availability:** High (Potential for ransomware or system instability).
## Remediation
### Patches
* No patch required; this is a service-side update rollout by Microsoft scheduled for **early to mid-November 2026**.
### Workarounds
* **For Administrators:** If there is a legitimate business need to receive these files, administrators must manually add `.msix` and `.msixbundle` to the `AllowedFileTypes` property of the `OwaMailboxPolicy`.
* **For Users:** Use secure file-sharing platforms (e.g., OneDrive, SharePoint) to exchange application packages rather than email attachments.
## Detection
* **Indicators of Compromise:** Unusual emails containing `.msix` or `.msixbundle` attachments from external or untrusted sources.
* **Detection Methods:**
* Monitor Exchange Online logs for blocked attachment attempts.
* Audit `OwaMailboxPolicy` changes to ensure the blocklist has not been unauthorizedly modified.
* Endpoint detection (EDR) for suspicious `AppInstaller.exe` activity or unauthorized application installations.
## References
* Microsoft Message Center: hxxps[://]mc[.]merill[.]net/message/MC1488841
* Microsoft Security Blog (App Installer Abuse): hxxps[://]www[.]microsoft[.]com/en-us/msrc/blog/2023/12/microsoft-addresses-app-installer-abuse
* Exchange Tech Community (Blocked File Types): hxxps[://]techcommunity[.]microsoft[.]com/blog/exchange/changes-to-file-types-blocked-in-outlook-on-the-web/874451