• Sublime Core Feed
Medium Severity

Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag

Description

The exploit involves tricking Outlook for Windows into displaying a fake domain while opening another one. This is achieved by adding a <base> HTML tag with a fake domain and a left-to-right mark (Unicode U+200E). Links within <a> tags will display the fake domain but open the actual domain when clicked on.

Sublime Security
Created Aug 17th, 2023 • Last updated Dec 10th, 2025
Source
type.inbound
and regex.contains(body.html.raw, 'base.{0,100}\x{200E}/>')
MQL Rule Console
DocsLearning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started