Search:     Advanced search
server monitoring

Vulnerability in Outlook could allow code execution (828040)

Article ID: 12092
Last updated: 27 Jan, 2009
Views: 391
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Vulnerability in Outlook could allow code execution (828040)

This script is Copyright (C) 2004-2008 Tenable Network Security

FamilyWindows : Microsoft Bulletins
Plugin ID12092
Bugtraq ID9827
CVE IDCVE-2004-0121

Description:

Synopsis :

Arbitrary code can be executed on the remote host through the email client.

Description :

The remote host is running a version of outlook which is vulnerable to a bug
which may allow Internet Explorer to execute script code in the Local Machine
zone and therefore let an attacker execute arbitrary programs on this host.

To exploit this bug, an attacker would need to send an special HTML message to
a user of this host.

Solution :

Microsoft has released a set of patches for Office 2002 and XP :

http://www.microsoft.com/technet/security/bulletin/ms04-009.mspx

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
This article was:   Helpful | Not Helpful
Prev   Next
Vulnerability in the Windows FTP Client Could Allow File...     Vulnerabilities in Microsoft XML Core Services Could Allow...