Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
DanieleS99
Contributor

MS.Outlook.CVE-2024-21413.Remote.Code.Execution

Hi,

For the new vulnerability CVE-2024-21413 there's a new signature from fortiguard.

But when I try to test it I have a doubt: If I try to send an email from my outlook, The body of the text message is encrypted with mapi over https so the signature not working.

There's a way to decrypt the content with fortigate? Otherwise this signature don't work at all.

I already enabled "mapi-over-https" in the SSL profile, but I saw only the Object of the mail in cleartext

 

Thanks

6 REPLIES 6
hbac
Staff
Staff

Hi @DanieleS99,

 

If you are using deep inspection, FortiGate will decrypt and inspect the packet. 

 

Regards, 

AEK
Honored Contributor II

Hello Daniele

MAPI is over HTTPS. You need to enable deep inspection for this so it can be scanned by IPS.

The tech tip below shows how to enable it.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-deep-inspection-and-import-a...

AEK
AEK
DanieleS99
Contributor

I have this type of SSL profile because if I do "Full SSL inspection" I don't see my certificate:photo.PNG

AEK
Honored Contributor II

If I understand well, here you have outlook client inside and want to access a mail server outside. If this is the case then you need to enable "Multiple Clients Connecting to Multiple Servers" instead of "Protecting SSL Server".

You can start here to learn about deep inspection for such usage.

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/122078/deep-inspection

 

AEK
AEK
DanieleS99

Sorry @AEK , I didn't explain myself well. What I want to do is scan the inbound emails to my mail server. I'm currently using the protecting ssl server which seems to scan the subject of the email but not the content of the message since I assume it's encrypted in IMAPS or something.

AEK
Honored Contributor II

Hi Daniele

See the protocol column on this screenshot.

smtp.png

If I'm not wrong this means that IPS checks for such attack in SMTP/SMTPS traffic, not in MAPI traffic. So you need to enable the IPS with this signature in the SMTP/S related policy.

AEK
AEK
Labels
Top Kudoed Authors