About Partners Contact Client Portal
LinkedIn Twitter
Services Industries Insights & Events Careers & Culture

Services

RubinBrown specializes in providing a comprehensive range of services to meet business and personal needs. Whether you require expert tax, strategic business consulting, audit services or more, RubinBrown's team of experienced professionals are here to support you.

View All Our Services
Assurance Services
Benefit Plan Audit Services Public Company Services SOC Examinations, IT Audit, & Third-Party Risk
Consulting Services
Business Process Improvement Services Business Restructuring & Bankruptcy Services Cyber Security Services Environmental, Social and Governance Services ERP & Enterprise Software Advisory Fraud & Forensics SOC Examinations, IT Audit, & Third-Party Risk Information Technology Services Litigation Services Mergers & Acquisitions Services Risk & Internal Audit Services Valuation Services
Entrepreneurial Services
Outsourced Accounting & Advisory Services
Tax Services
Federal Tax Services Private Client Services Credits & Incentives Services State & Local Tax Services
RubinBrown Advisors RubinBrown Corporate Finance

Industries

At RubinBrown, we bring experience across a range of industries. Our experience enables our professionals to offer tailored solutions catering to the intricacies of each sector. Our professionals have years of focused engagement and skills, allowing them to navigate industry-specific challenges to benefit our clients.

View All Our Industries
Colleges & Universities Construction Gaming Healthcare Law Firms Life Sciences & Technology Manufacturing & Distribution Not-For-Profit Private Equity Public Sector Real Estate Transportation & Dealerships

Insights & Events

At RubinBrown, we provide valuable insights detailing emerging trends and industry-specific information. Our events, hosted virtually and in-person, keep you informed and connected to the topics and industries that matter most to you and your organization.

View All Insights & Events
Jun 11

RubinBrown’s Leveraging Technology for Business Success

Learn More & Register
Jun 17

RubinBrown’s Rural Health Webinar Series

Learn More & Register

RubinBrown Sports Betting Index: March 2025 Analysis

Learn More

Tax Bill Watch 2025: Budget Resolution Compromise

Learn More

Careers & Culture

At RubinBrown, we are inspired team members, working as one firm, living our core values, and Being Our Best for Others while delivering totally satisfied clients. We invite you to learn more about the Firm's culture, the Be Your Best for Others mentality, and explore the available opportunities at RubinBrown.

Discover Our Culture
Baker Tilly International Campus Recruiting Diversity & Inclusion Experienced Recruiting Locations & Contact Information Partners RubinBrown Charitable Foundation Join The Team
Back to Insights

Trouble in your Inbox: OLE Remote Code Execution

Contact Us

Trouble in your Inbox: OLE Remote Code Execution

Contact Us

A new Outlook vulnerability has been discovered that represents a significant risk–even if you do not open the email or click on a link. Ask your IT support team to implement the patch—or take precautions to protect yourself.

On January 14, 2025, security researchers at Trend Micro released information regarding a zero-day exploit discovered in most versions of Microsoft Outlook that could allow threat actors to execute malware on your system even if you don't open an attachment or click a link. We'll examine this vulnerability, CVE-2025-21298, and find out what all the fuss is about.

How serious is it?

Pretty serious. It was assigned a CVSS score of 9.8 (out of 10) due to the ability for Remote Code Execution (RCE) and the ease of possible exploitation.

How does it work?

This vulnerability exploits the Object Linking and Embedding (OLE) technology in Windows that allows for documents and other objects to be linked and embedded into emails and other documents. The threat actor creates an email with specially crafted malware in it, and the malware can be activated when the email displays in Outlook's "Preview" window if you're running an affected version of Outlook. 

What can I do about it?

Microsoft has released a patch, so updating Outlook to the newest version will solve the problem. However, if you can't update just yet, there are several workarounds:

  1. RTF file attachments are risky. If you get one from an untrusted or unexpected source, treat it as a possible threat. 
  2. Make sure your email accounts are configured to have the least possible privilege—daily-use email accounts should not have admin rights. This will prevent a bad day from becoming a worse day in the event of an attack.
  3.  Read emails in "plain text" format. This will keep pictures, links, and specialized fonts from being used. Your email won't look as good, but on the other hand, you don't get hacked.

From your file menu, go to "Options."
 Outlook-1.jpg
Then go to Trust Center and click "Trust Center Settings."
 Outlook-2.png
From the "Email Security" tab, click "Read all standard mail in plain text."

Outlook-3.png
If you're in a high-risk environment, also click "Read all digitally signed email in plain text."
 
Once you've confirmed that your Outlook has been patched and the vulnerability is remediated, you can follow the same path and uncheck the box to get your "regular" email appearance back.

Quick action on vulnerabilities such as this can mean the difference between safety and disaster; confirm with your IT staff or external provider to ensure that your mailbox is safe and up to date.

If you have questions about this new vulnerability or any other cyber security topics, RubinBrown's Cyber Security Services team has experts ready to assist. 
 

 

Published: 01/20/2025

Readers should not act upon information presented without individual professional consultation.

Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.

 

Contact Us:

Talk to Our Experts

Robert Rudloff, CISSP, CISA, QSA, CMMC RPA Partner rob.rudloff@rubinbrown.com 303-952-1220

Be Your Best for Others at RubinBrown

At RubinBrown, our firm fosters a culture built upon five vision points, and are guided by our philosophy of Being Our Best for Others. Discover how you can be your best at RubinBrown today by visiting our Careers & Culture Overview for available opportunities and more.

Discover Our Culture

Join Our Mailing List

RubinBrown periodically sends breaking regulatory updates, technical summaries, industry-specific information and event (in-person and virtual) invitations through electronic newsletters.

Sign Up for Our Communications
1-800-678-3134 Certified Public Accountants & Business Consultants

Ranked a Top 50 Accounting Firm by Inside Public Accounting

Firm News Disclaimers Privacy Policy Client Payment © 2025 RubinBrown LLP
LinkedIn Twitter RubinBrown Executive Recruiting RubinBrown Advisors RubinBrown Corporate Finance