{"id":31098,"date":"2023-07-25T06:44:58","date_gmt":"2023-07-25T04:44:58","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=31098"},"modified":"2023-07-25T06:58:49","modified_gmt":"2023-07-25T04:58:49","slug":"outlook-blocks-hyperlinks-after-july-2023-update-a-workaround-from-microsoft","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2023\/07\/25\/outlook-blocks-hyperlinks-after-july-2023-update-a-workaround-from-microsoft\/","title":{"rendered":"Outlook blocks hyperlinks after July 2023 update; a workaround from Microsoft"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2012\/07\/Office1.jpg\" width=\"55\" height=\"60\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2023\/07\/25\/outlook-blockt-hyperlinks-nach-juli-2023-update-workaround-von-microsoft\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Since installing the July 11, 2023 security updates that closed a Security Feature Bypass vulnerability in Outlook, some users can no longer use hyperlinks without restrictions. Either a warning comes up or the hyperlinks no longer work. Now Microsoft has spoken out and has also suggested a workaround.<\/p>\n<p><!--more--><\/p>\n<h2>Hyperlinks causes a Outlook warning<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg09.met.vgwort.de\/na\/e19e65edd84749b4aefeea0c57eaf21f\" alt=\"\" width=\"1\" height=\"1\" \/>I had picked up on July 19, 2023 in the blog post <a href=\"https:\/\/borncity.com\/win\/2023\/07\/19\/outlook-2016-links-broken-after-update-from-july-11-2023-kb5002427-security-warning-appears-when-clicking-links\/\" target=\"_blank\" rel=\"noopener\">Outlook 2016: Links broken after update from July 11, 2023 (KB5002427) \u2013 Security warning appears when clicking links<\/a>. If users select links to open in Outlook after installing the security updates, a security warning appears.<\/p>\n<blockquote><p>Microsoft Outlook Security Notice<\/p>\n<p>Microsoft Office has identified a potential security concern.<br \/>\nThis location may be unsafe.<\/p><\/blockquote>\n<p>The issue was indeed related to Office 2016 and the KB5002427 security update for Outlook 2016 in the post. However, the flaw also occurs in Outlook from Office 365 when the July 2023 security updates to close the Microsoft Outlook Security Feature Bypass vulnerability <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2023-35311\" target=\"_blank\" rel=\"noopener\">CVE-2023-35311<\/a> are installed. Phil had then reached out in <a href=\"https:\/\/www.borncity.com\/blog\/2023\/07\/19\/outlook-2016-links-nach-update-vom-11-juli-2023-kb5002427-kaputt-sicherheitswarnung-erscheint-bei-linkanwahl\/#comment-152816\" target=\"_blank\" rel=\"noopener\">this German comment<\/a> and wrote:<\/p>\n<blockquote><p>The problem only occurs when the UNC path is used as FQDN. Without domain it works without problems.<\/p>\n<p>Under Control Panel, Internet Options, Security, Trusted Sites you can enter the FQDN, then it works for us (file:\/\/*.domain.local).<\/p><\/blockquote>\n<p>This was also confirmed by another user.<\/p>\n<h2>Microsoft confirms the problem<\/h2>\n<p>Via the colleagues at <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-shares-fix-for-some-outlook-hyperlinks-not-opening\/\" target=\"_blank\" rel=\"noopener\">Bleeping Computer<\/a> I came across the Microsoft support post <a href=\"https:\/\/support.microsoft.com\/en-us\/office\/outlook-blocks-opening-fqdn-and-ip-address-hyperlinks-after-installing-protections-for-microsoft-outlook-security-feature-bypass-vulnerability-released-july-11-2023-4a5160b4-76d0-465b-9809-60837bbd35a8\" target=\"_blank\" rel=\"noopener\">Outlook blocks opening FQDN and IP address hyperlinks after installing protections for Microsoft Outlook Security Feature Bypass Vulnerability released July 11, 2023<\/a> released July 11, 2023. There the vendor confirms the problem for Outlook for Microsoft 365 and writes:<\/p>\n<blockquote><p>When you click on links in emails in Outlook Desktop where the path is to a fully qualified domain name (FQDN) or IP address you may see the following:<\/p>\n<p>An Outlook warning dialog with the error \"Something unexpected went wrong with this URL\"<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2023\/07\/09788fb3-a029-46e4-9192-f1563f7c7109.png\" \/><\/p>\n<ul>\n<li>Silent failure for the untrusted file.<\/li>\n<\/ul>\n<\/blockquote>\n<p>If the user tries to open links in e-mail in Outlook Desktop where the path points to either an FQDN or an IP address or a hostname path, a dialog box appears with the warning I mentioned above, \"Microsoft Office has detected a potential security risk. This location may not be secure.\" is displayed. According to Microsoft, this behavior is to be expected. The support article cites the closed vulnerabilities and the Outlook 2013\/2016 update as the cause.<\/p>\n<h2>Suggested workarounds from Microsoft<\/h2>\n<p>Microsoft then suggested two workarounds in the support article on how to fix the above issues. The first suggestion was also outlined by blog reader Phil in <a href=\"https:\/\/www.borncity.com\/blog\/2023\/07\/19\/outlook-2016-links-nach-update-vom-11-juli-2023-kb5002427-kaputt-sicherheitswarnung-erscheint-bei-linkanwahl\/#comment-152816\" target=\"_blank\" rel=\"noopener\">this German comment<\/a>.<\/p>\n<ol>\n<li>Go to Windows\u00a0<em>Settings.<\/em><\/li>\n<li>Search for and open\u00a0<em>Internet Options<\/em>.<\/li>\n<li>Click the\u00a0<em>Security\u00a0<\/em>tab, then select\u00a0<em>Trusted Sites<\/em>.<\/li>\n<li>Add the URL, UNC, FQDN path that you want to allow to \"<em>Add this website to the zone<\/em>\" (for example, add\u202ffile:\/\/server.usa.corp.com).<\/li>\n<\/ol>\n<p>In a nutshell: Add the FQDN or IP address path to the Trusted Sites zone. However, Microsoft writes that this intervention makes the system more vulnerable to attacks by malicious users or malicious software such as viruses. In addition, make sure that the FQDN or IP address added to the trusted sites is a valid URL path for the company or network.<\/p>\n<p>Instead of manually adding the URL to the trusted website zone in the Internet options, the whole thing can also be distributed via group policy. Microsoft provides a short note about this possibility in the <a href=\"https:\/\/support.microsoft.com\/en-us\/office\/outlook-blocks-opening-fqdn-and-ip-address-hyperlinks-after-installing-protections-for-microsoft-outlook-security-feature-bypass-vulnerability-released-july-11-2023-4a5160b4-76d0-465b-9809-60837bbd35a8\" target=\"_blank\" rel=\"noopener\">support article<\/a>. Perhaps it will help those affected.<\/p>\n<p><strong>Similar articles<br \/>\n<\/strong><a href=\"https:\/\/borncity.com\/win\/2023\/07\/19\/outlook-2016-links-broken-after-update-from-july-11-2023-kb5002427-security-warning-appears-when-clicking-links\/\" rel=\"bookmark\">Outlook 2016: Links broken after update from July 11, 2023 (KB5002427) \u2013 Security warning appears when clicking links<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/07\/22\/outlook-appointments-automatically-become-teams-meetings\/\" rel=\"bookmark\">Outlook appointments automatically become teams meetings<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/07\/11\/outlook-startup-asks-for-re-open-windows-options-to-disable-missing\/\" rel=\"bookmark\">Outlook startup asks for \"re-open windows\", options to disable missing<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/07\/07\/outlook-com-search-issue-july-6-7-2023-ms-teams-duplicate-contacts-bug-unfixed-since-end-of-march-2023\/\" rel=\"bookmark\">Outlook.com search issue ;(July 6\/7, 2023); MS Teams \"duplicate contacts\" bug unfixed since end of March 2023<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/07\/04\/windows-10-11-june-update-can-prevent-outlook-and-app-from-starting-bug-fix-available\/\" rel=\"bookmark\">Windows 10\/11: June update can prevent Outlook and App from starting, bug fix available<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/07\/03\/microsoft-365-business-outlook-shows-black-font-on-black-background\/\" rel=\"bookmark\">Microsoft 365 (Business) Outlook shows black font on black background<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/06\/21\/microsoft-365-microsoft-shares-s-workaround-for-hanging-slow-running-outlook\/\" rel=\"bookmark\">Microsoft 365: Microsoft shares a workaround for hanging\/slow running Outlook<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/06\/17\/outlook-365-damages-pdf-and-office-files-since-april-2023\/\" rel=\"bookmark\">Outlook 365 damages PDF and Office files since April 2023<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/06\/02\/microsoft-office-2304-build-16327-20308-outlook-displays-self-signed-e-mails-as-text\/\" rel=\"bookmark\">Microsoft Office 2304 (Build 16327.20308): Outlook displays self-signed e-mails as text<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/05\/15\/microsoft-is-installing-outlook-preview-without-permission\/\" rel=\"bookmark\">Microsoft is installing Outlook-Preview without permission<\/a><\/p>\n<p class=\"entry-title\"><a href=\"https:\/\/borncity.com\/win\/2023\/07\/13\/microsoft-office-updates-july-11-2023\/\" rel=\"bookmark\">Microsoft Office Updates (July 11, 2023)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Since installing the July 11, 2023 security updates that closed a Security Feature Bypass vulnerability in Outlook, some users can no longer use hyperlinks without restrictions. Either a warning comes up or the hyperlinks no longer work. Now Microsoft has &hellip; <a href=\"https:\/\/borncity.com\/win\/2023\/07\/25\/outlook-blocks-hyperlinks-after-july-2023-update-a-workaround-from-microsoft\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,11,580,1547,22],"tags":[47,395],"class_list":["post-31098","post","type-post","status-publish","format-standard","hentry","category-issue","category-office","category-security","category-software","category-update","tag-issue","tag-outlook"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/31098","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=31098"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/31098\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=31098"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=31098"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=31098"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}