Update attack-surface-reduction.md

This commit is contained in:
Denise Vangel-MSFT 2020-07-21 11:30:52 -07:00 committed by GitHub
parent 4de60604f2
commit e39d503b80
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -343,7 +343,7 @@ GUID: `b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba4`
### Block Office communication application from creating child processes
This rule prevents Outlook from creating child processes, while till allowing legitimate Outlook functions.
This rule prevents Outlook from creating child processes, while still allowing legitimate Outlook functions.
This protects against social engineering attacks and prevents exploit code from abusing vulnerabilities in Outlook. It also protects against [Outlook rules and forms exploits](https://blogs.technet.microsoft.com/office365security/defending-against-rules-and-forms-injection/) that attackers can use when a user's credentials are compromised.