In response to the security breach concerning the OneNote file, Secuserve has integrated into its e-securemail services the ability to block messages containing attachments with the *.one extension.
As a reminder, this flaw allows attackers to remotely execute malicious VBS code.
For more information, please refer to the article published in the cert report: https://www.cert.ssi.gouv.fr/avis/CERTFR-2022-AVI-1102/.
As with MalWare sending attacks (Emotet, Ryuk, Egreror and its variants), we recommend that you be vigilant (even if the sender seems legitimate) when receiving emails containing a *.one attachment, and block it by activating content filtering from your administration interface, in Configuration > Domain filtering, then in the Content > Office block and select *.one as below.
Back to news
Secuserve