Microsoft Outlook Express Address Book Spoofing Vulnerability
BID:2823
Info
Microsoft Outlook Express Address Book Spoofing Vulnerability
| Bugtraq ID: | 2823 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2001 12:00AM |
| Updated: | Jun 05 2001 12:00AM |
| Credit: | This vulnerability was posted to BugTraq on June 5th, 2001 by 3APA3A <[email protected]>. |
| Vulnerable: |
Microsoft Outlook Express for MacOS 5.0 Microsoft Outlook Express for MacOS 4.5 Microsoft Outlook Express 4.72.3612 Microsoft Outlook Express 4.72.3120 Microsoft Outlook Express 4.72.2106 Microsoft Outlook Express 4.27.3110 Microsoft Outlook Express 5.5 Microsoft Outlook 98 0 Microsoft Outlook 97 8.2.4212 Microsoft Outlook 97 0 Microsoft Outlook 2000 0 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Express Address Book Spoofing Vulnerability
Outlook Express is the standard e-mail client that is shipped with Microsoft Windows 9x/ME/NT.
The address book in Outlook Express is normally configured to make entries for all addresses that are replied to by the user of the mail client. An attacker may construct a message header that tricks Address Book into making an entry for an untrusted user under the guise of a trusted one. This is done by sending a message with a misleading "From:" field. When the message is replied to then Address Book will make an entry which actually replies to the attacker.
Outlook Express is the standard e-mail client that is shipped with Microsoft Windows 9x/ME/NT.
The address book in Outlook Express is normally configured to make entries for all addresses that are replied to by the user of the mail client. An attacker may construct a message header that tricks Address Book into making an entry for an untrusted user under the guise of a trusted one. This is done by sending a message with a misleading "From:" field. When the message is replied to then Address Book will make an entry which actually replies to the attacker.
Exploit / POC
Microsoft Outlook Express Address Book Spoofing Vulnerability
This example supplied by by 3APA3A <[email protected]>:
Situation: 2 good users Target1 and Target2 with addresses [email protected] and
[email protected] and one bad user Attacker, [email protected]. Imagine Attacker wants to get
messages Target1 sends to Target2. Scenario:
1. Attacker composes message with headers:
From: "[email protected]" <[email protected]>
Reply-To: "[email protected]" <[email protected]>
To: Target1 <[email protected]>
Subject: how to catch you on Friday?
and sends it to [email protected]
2. Target1 receives mail, which looks absolutely like mail received from
[email protected] and replies it. Reply will be received by Attacker. In this case
new entry is created in address book pointing NAME "[email protected]" to
ADDRESS [email protected].
3. Now, if while composing new message Target1 directly types e-mail
address [email protected] instead of Target2, Outlook will compose address as
"[email protected]" <[email protected]> and message will be received by Attacker.
This example supplied by by 3APA3A <[email protected]>:
Situation: 2 good users Target1 and Target2 with addresses [email protected] and
[email protected] and one bad user Attacker, [email protected]. Imagine Attacker wants to get
messages Target1 sends to Target2. Scenario:
1. Attacker composes message with headers:
From: "[email protected]" <[email protected]>
Reply-To: "[email protected]" <[email protected]>
To: Target1 <[email protected]>
Subject: how to catch you on Friday?
and sends it to [email protected]
2. Target1 receives mail, which looks absolutely like mail received from
[email protected] and replies it. Reply will be received by Attacker. In this case
new entry is created in address book pointing NAME "[email protected]" to
ADDRESS [email protected].
3. Now, if while composing new message Target1 directly types e-mail
address [email protected] instead of Target2, Outlook will compose address as
"[email protected]" <[email protected]> and message will be received by Attacker.
Solution / Fix
Microsoft Outlook Express Address Book Spoofing Vulnerability
Solution:
The vendor has been notified and will address the issue in an upcoming service pack.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has been notified and will address the issue in an upcoming service pack.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Outlook Express Address Book Spoofing Vulnerability
References:
References:
- Microsoft Outlook Express address book vulnerability (SECURITY.NNOV)