Outlook Express/Windows Mail MHTML URI Handler Information Disclosure Vulnerability
BID:17717
Info
Outlook Express/Windows Mail MHTML URI Handler Information Disclosure Vulnerability
| Bugtraq ID: | 17717 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2006-2111 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2006 12:00AM |
| Updated: | Jun 14 2007 04:09PM |
| Credit: | codedreamer is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Windows Mail 0 Microsoft Outlook Express 6.0 SP2 Microsoft Outlook Express 6.0 SP1 Microsoft Outlook Express 6.0 Microsoft Outlook Express 5.5 SP2 Microsoft Outlook Express 5.5 SP1 Microsoft Outlook Express 5.5 |
| Not Vulnerable: | |
Discussion
Outlook Express/Windows Mail MHTML URI Handler Information Disclosure Vulnerability
Outlook Express and Windows Mail are prone to a cross-domain information-disclosure vulnerability.
This vulnerability may let a malicious website access properties of a site in an arbitrary external domain in the context of the victim user's browser. Attackers could exploit this issue to gain access to sensitive information (such as cookies or passwords) that is associated with the external domain.
This issue was previously reported as an Internet Explorer vulnerability, but the affected component is found to be part of Outlook Express and Windows Mail. Microsoft confirmed that this is an Outlook Express/Windows Mail vulnerability that can also be exploited through Internet Explorer.
Outlook Express and Windows Mail are prone to a cross-domain information-disclosure vulnerability.
This vulnerability may let a malicious website access properties of a site in an arbitrary external domain in the context of the victim user's browser. Attackers could exploit this issue to gain access to sensitive information (such as cookies or passwords) that is associated with the external domain.
This issue was previously reported as an Internet Explorer vulnerability, but the affected component is found to be part of Outlook Express and Windows Mail. Microsoft confirmed that this is an Outlook Express/Windows Mail vulnerability that can also be exploited through Internet Explorer.
Exploit / POC
Outlook Express/Windows Mail MHTML URI Handler Information Disclosure Vulnerability
The following exploit demonstrates this issue:
The following exploit demonstrates this issue:
Solution / Fix
Outlook Express/Windows Mail MHTML URI Handler Information Disclosure Vulnerability
Solution:
The vendor has released an advisory to address this issue in supported versions of affected applications. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Microsoft Windows Mail 0
Microsoft Outlook Express 6.0 SP2
Solution:
The vendor has released an advisory to address this issue in supported versions of affected applications. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Microsoft Windows Mail 0
-
Microsoft Cumulative Security Update for Outlook Express for Windows Vista (KB929123)
Windows Vista
http://www.microsoft.com/downloads/details.aspx?FamilyId=ee57de19-44ea -48f2-ae28-e76fd2018633&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows Vista for x64-based Systems (KB929123)
Windows Vista x64 Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=343db20f-7794 -4423-b11d-885329fbdf78&displaylang=en
Microsoft Outlook Express 6.0 SP2
-
Microsoft Cumulative Security Update for Outlook Express for Windows Server 2003 (KB929123)
Windows Server 2003 Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=93808a74-035c -4ab7-9283-c693d7bd82be&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows Server 2003 (KB929123)
Windows Server 2003 Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyId=93808a74-035c -4ab7-9283-c693d7bd82be&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows Server 2003 for Itanium-based Systems (KB
Windows Server 2003 with SP1 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?FamilyId=2e62e96e-6571 -437d-a612-99175ac39025&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows Server 2003 for Itanium-based Systems (KB
Windows Server 2003 with SP2 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?FamilyId=2e62e96e-6571 -437d-a612-99175ac39025&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows Server 2003 x64 Edition (KB929123)
Windows Server 2003 x64 Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=f63323a9-e285 -45e5-84bd-71ae9da126e3&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows Server 2003 x64 Edition (KB929123)
Windows Server 2003 x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyId=f63323a9-e285 -45e5-84bd-71ae9da126e3&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows XP (KB929123)
Windows XP Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyId=27cca556-0872 -4803-b610-4c895ceb99aa&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows XP x64 Edition (KB929123)
Windows XP Professional x64 Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=1ea813bf-bddb -40f0-8960-b9debc8413e7&displaylang=en -
Microsoft Cumulative Security Update for Outlook Express for Windows XP x64 Edition (KB929123)
Windows XP Professional x64 Edition Service Pack 2
http://www.microsoft.com/downloads/details.aspx?FamilyId=1ea813bf-bddb -40f0-8960-b9debc8413e7&displaylang=en
References
Outlook Express/Windows Mail MHTML URI Handler Information Disclosure Vulnerability
References:
References:
- Internet Explorer Arbitrary Content Disclosure Vulnerability Test (codedreamer)
- Mhtml MSIE Exploitation Framework (RSnake)
- IE7 is a Source of Problem - Secunia IE7 Release Incident of October 2006 ("LIUDIEYU dot COM"
) - Information on Reports of IE 7 Vulnerability (Microsoft)
- Microsoft Homepage (Microsoft)
- Microsoft Security Bulletin MS07-034 - Critical (Microsoft)
- Vulnerability Note VU#783761 Microsoft Windows 'MHTML' protocol handler fails to (US-CERT)