Latest from Sophos, has moved to Dev team. Should be fixed globally now without needing the exploit mitigation disabled.
We've identified an issue with a new DCOMLockdown mitigation technique that is part of Intercept X protections, which wecurrently test, that could cause Outlook to crash, logging the following entryin the application Eventlog:
Error 19.01.2021 17:29:39 ApplicationError 1000 (100)
Faulting application name: OUTLOOK.EXE, version: 16.0.13530.20376, time stamp:0x5ffa7614
Faulting module name: ucrtbase.dll, version: 10.0.19041.546, time stamp:0x43cbc11d
Exception code: 0xc0000409
Fault offset: 0x000000000007287e
Faulting process id: 0x6d24
Faulting application path: C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
Faulting module path: C:\WINDOWS\System32\ucrtbase.dll
Due to the low number of Support Cases we received on the reported issue, wesuspect the crashes to be influenced by another third party application (likean Outlook Add-in), which is currently under investigation by our DevelopmentTeams.
We are going to mitigate the reported issue by disabling the new DCOM Lockdowntechnique globally until we understood what exactly triggered themitigation/crash and have a fix for it in place. This DCOM Lockdownmitigation is a sub-mitigation of the Lockdown family that has not yet beenofficially announced/release and we will only disable this sub-mitigation. Allother Lockdown mitigations will remain active.
All of your Endpoints should receive the today. Once the Endpoints received theupdate, the following registry keys should switch to 0:
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos EndpointDefense\EndpointFlags"
"hmpa.lockdownmemory.v2.enforce"="0"
"hmpa.lockdownmemory.v2.silent"="0"
We recommend to ensure to remove any Exploit Mitigaiton Exclusions forOutlook.exe that had been set while the issue was present. Also, the ThreatProtection policy setting 'Protect office applications' should be kept enabledto retain full protection.
Your issue has been escalated to our development team with the above referencenumber. Issues are prioritised based on severity and customer impact. Iwill get back to you with an update on the investigation process by February9th or earlier if Development shares any feedback.