Urgent.News

What's breaking now, across thousands of outlets.

Science

Microsoft extends the Outlook naughty step with two more file types

You didn't really want to be sending around .msix and .msixbundle files, did you?

Microsoft extends the Outlook naughty step with two more file types

Microsoft is expanding its Outlook block list to include two additional file types, .msix and .msixbundle, aimed at bolstering security. These file types are utilized for Windows application packages and bundles. The modification impacts Outlook for Windows New and Outlook on the Web in Exchange Online. Consequently, users of the affected clients will be unable to download or open attachments with these extensions by default, as blindly installing a malicious .msix package could jeopardize a device.

While Microsoft acknowledged that the file types are infrequently used, there are legitimate reasons for their inclusion in emails. Administrators seeking to permit these attachments can modify the AllowedFileTypes property of the relevant OwaMailboxPolicy before the rollout, set for early to mid-November 2026. This update is part of Microsoft's continuous efforts to enhance security and safeguard organizations from potentially unsafe file attachments.

Microsoft's application packaging system has faced scrutiny in the past, leading to the disabling of the ms-appinstaller protocol handler by default in December 2023 due to its misuse by attackers to distribute malware. The attachment block serves as an additional layer of protection, unless administrators explicitly permit these file types.

Other file types blocked by Outlook on the Web include .py Python files, .ps1 PowerShell files, and .cab files. The inclusion of .msix and .msixbundle may seem surprising, given the potential damage malicious packages can inflict on a system. While disguising an attachment's extension or sharing a download link may bypass the restriction, neither ensures the package's safety.

Convincing someone to download and install it remains a viable method for malicious actors, even with Windows' other safeguards in place.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Science

More from Tuesday 6 October →