{"id":29273,"date":"2023-04-05T13:11:15","date_gmt":"2023-04-05T11:11:15","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=29273"},"modified":"2023-04-05T13:11:38","modified_gmt":"2023-04-05T11:11:38","slug":"ms-onenote-will-block-120-dangerous-file-types-in-future","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2023\/04\/05\/ms-onenote-will-block-120-dangerous-file-types-in-future\/","title":{"rendered":"MS OneNote will block 120 dangerous file types in future"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2012\/07\/Office1.jpg\" width=\"55\" height=\"60\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2023\/04\/05\/ms-onenote-soll-knftig-120-gefhrliche-filetypen-blockieren\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Microsoft is reacting to the fact that OneNote is now being abused as a malware sling for systems. The application is supposed to block 120 dangerous file types in the future, so that they can no longer be abused for malware attacks by downloads from the Internet.<\/p>\n<p><!--more--><\/p>\n<h2>OneNote as a security risk<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg07.met.vgwort.de\/na\/3aedbb5afcc7421d98844eedacce0ad3\" alt=\"\" width=\"1\" height=\"1\" \/>Since Microsoft and administrators of Windows systems have been investing more in macro security, attacks via this vector have become more difficult. Meanwhile, cybercriminals are using OneNote as a gateway to launch attacks or spread malware. Bleeping Computer colleagues had already pointed out in January 2023 that hackers are making use of Microsoft OneNote attachments to spread malware (see <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-now-use-microsoft-onenote-attachments-to-spread-malware\/\">Hackers now use Microsoft OneNote attachments to spread malware<\/a>). The basis for this warning is a<a href=\"https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/trojanized-onenote-document-leads-to-formbook-malware\/\" target=\"_blank\" rel=\"noopener\"> blog post<\/a> by SpiderLabs, which in December 2022 had come across Trojans that were included in OneNote files with the .one extension as email attachments.<\/p>\n<p>If the user opens this attachment, it opens in OneNote. If the user clicks away a warning that a file is being opened from OneNote, a Windows Script file script embedded in the .one file can be executed. This is then capable of causing further mischief. Specifically, the Emotet Trojan is increasingly being spread via this vector (see my German blog post <a href=\"https:\/\/www.borncity.com\/blog\/2023\/03\/20\/emotet-ist-im-mrz-2023-zurck-verbreitung-der-malware-ber-onenote-anhnge\/\">Emotet ist im M\u00e4rz 2023 zur\u00fcck, Verbreitung der Malware \u00fcber OneNote-Anh\u00e4nge<\/a>).<\/p>\n<p>In mid-March 2023, I had pointed this out in the post <a href=\"https:\/\/borncity.com\/win\/2023\/03\/19\/improved-office-macro-security-leads-to-new-attack-methods-via-onenote-and-other-filetypes\/\">Improved Office macro security leads to new attack methods via OneNote and other filetypes<\/a> and linked to the post <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/how-to-prevent-microsoft-onenote-files-from-infecting-windows-with-malware\/\">How to prevent Microsoft OneNote files from infecting Windows with malware<\/a> by Bleeping Computer. There were hints how to mitigate the attack vector. The group policies to secure OneNote can be found in the <a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=49030\">Microsoft 365\/Microsoft Office group policy templates<\/a>. The required policies are described in Bleeping Computer's post.<\/p>\n<h2>Microsoft plans further protection measures<\/h2>\n<p>I haven't followed the topic in detail, but I came across the following <a href=\"https:\/\/twitter.com\/BleepinComputer\/status\/1641556008639115266\" target=\"_blank\" rel=\"noopener\">tweet<\/a> from the colleagues at Bleeping Computer. The message of the post <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-onenote-will-block-120-dangerous-file-extensions\/\" target=\"_blank\" rel=\"noopener\">Microsoft OneNote will block 120 dangerous file extensions<\/a> is that Microsoft wants to block 120 dangerous file types in OneNote in the future.<\/p>\n<p><a href=\"https:\/\/twitter.com\/BleepinComputer\/status\/1641556008639115266\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"https:\/\/i.imgur.com\/v3HqdDJ.png\" \/><\/a><\/p>\n<p>In an entry in the <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/roadmap?filters=OneNote%2CIn%20development&amp;searchterms=122277\" target=\"_blank\" rel=\"noopener\">Microsoft 365 roadmap<\/a> dated March 10, 2023, the company first announced that OneNote would receive improved security. The document <a href=\"https:\/\/learn.microsoft.com\/en-us\/deployoffice\/security\/onenote-extension-block\" target=\"_blank\" rel=\"noopener\">OneNote blocks embedded files that have dangerous extensions<\/a>, dated March 28, 2023, now lists the details of the upcoming change. What will change as a result? Previously, there was a warning in OneNote when users tried to open files with MotW flags (i.e. Internet downloads). The user could still open the file. In the future, once the update is armed, the warning will say \"Your administrator has blocked this file type from being opened in OneNote.\"<\/p>\n<p><img decoding=\"async\" title=\"OneNote blockt Dateityp\" src=\"https:\/\/i.imgur.com\/7ZfZTdp.png\" alt=\"OneNote blockt Dateityp\" \/><\/p>\n<p>A <a href=\"https:\/\/support.microsoft.com\/en-us\/office\/blocked-attachments-in-outlook-434752e1-02d3-4e90-9124-8b81e49a8519#:~:text=File%20types%20blocked%20in%20Outlook\" target=\"_blank\" rel=\"noopener\">Microsoft 365 support document<\/a> lists 120 file types that should be blocked from loading in OneNote, Outlook, Word, Excel and PowerPoin as Internet downloads, i.e. with Mark of the Web flag (MotW). However, in the Microsoft 365 support document there are hints on how to share such files safely (e.g. upload to OneDrive or SharePoint with sending a link).<\/p>\n<p>In addition, the article <a href=\"https:\/\/learn.microsoft.com\/en-us\/deployoffice\/security\/onenote-extension-block#versions-of-onenote-affected-by-this-change\" target=\"_blank\" rel=\"noopener\">OneNote blocks embedded files that have dangerous extensions<\/a> rovides hints on how to block further file name extensions. A <a href=\"https:\/\/learn.microsoft.com\/en-us\/deployoffice\/security\/onenote-extension-block#allow-file-extensions-that-are-blocked-by-default\" target=\"_blank\" rel=\"noopener\">separate section<\/a> is also dedicated to the question of how to allow the file extensions that are blocked by default.<\/p>\n<h2>When it is rolled out?<\/h2>\n<p>Microsoft plans to roll out the change between late April 2023 and late May 2023 in version 2304 in the Current Channel (Preview) for OneNote for Microsoft 365 on Windows devices. The <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/roadmap?filters=OneNote%2CIn%20development&amp;searchterms=122277\" target=\"_blank\" rel=\"noopener\">Microsoft 365 roadmap<\/a> said \"Rollout starts in April 2023\", more details can be found in the Microsoft document <a href=\"https:\/\/learn.microsoft.com\/en-us\/deployoffice\/security\/onenote-extension-block#versions-of-onenote-affected-by-this-change\" target=\"_blank\" rel=\"noopener\">Versions of OneNote affected by this change<\/a>. The colleagues at Bleeping Computer have compiled all the details <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-onenote-will-block-120-dangerous-file-extensions\/\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n<p>This new security feature is also said to be coming to retail versions of Microsoft Office 2016 (Current Channel), 2019 and 2021. Not provided is this new security feature in the volume license versions of Office, such as Office Standard 2019 or Office LTSC Professional Plus 2021. The new feature is also not coming to OneNote for Web, OneNote for Windows 10, OneNote for Mac, and OneNote on Android or iOS devices.<\/p>\n<p><strong>Similar articles:<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/03\/19\/improved-office-macro-security-leads-to-new-attack-methods-via-onenote-and-other-filetypes\/\">Improved Office macro security leads to new attack methods via OneNote and other filetypes<\/a><br \/>\n<a href=\"https:\/\/www.borncity.com\/blog\/2023\/03\/20\/emotet-ist-im-mrz-2023-zurck-verbreitung-der-malware-ber-onenote-anhnge\/\" target=\"_blank\" rel=\"noopener\">Emotet ist im M\u00e4rz 2023 zur\u00fcck, Verbreitung der Malware \u00fcber OneNote-Anh\u00e4nge<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft is reacting to the fact that OneNote is now being abused as a malware sling for systems. The application is supposed to block 120 dangerous file types in the future, so that they can no longer be abused for &hellip; <a href=\"https:\/\/borncity.com\/win\/2023\/04\/05\/ms-onenote-will-block-120-dangerous-file-types-in-future\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,580],"tags":[874,69],"class_list":["post-29273","post","type-post","status-publish","format-standard","hentry","category-office","category-security","tag-onenote","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/29273","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=29273"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/29273\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=29273"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=29273"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=29273"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}