Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability
BID:28548
Info
Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability
| Bugtraq ID: | 28548 |
| Class: | Design Error |
| CVE: |
CVE-2008-3068 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2008 12:00AM |
| Updated: | May 07 2015 05:30PM |
| Credit: | Alexander Klink |
| Vulnerable: |
Microsoft Windows Live Mail 2008 0 Microsoft Outlook 2007 0 Microsoft Office 2007 SP1 Microsoft Office 2007 0 Microsoft Crypto API 0 |
| Not Vulnerable: | |
Discussion
Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability
Microsoft's Crypto API library is prone to an information-disclosure vulnerability because HTTP requests to arbitrary hosts and ports may be automatically triggered when validating X.509 certificates.
Successful exploits allow attackers to trigger HTTP requests to arbitrary hosts and ports without confirmation or notification to unsuspecting users. Attackers may use this for determining when email and documents are read, for port scanning, or for aiding in other attacks.
The following products are known to exhibit this issue:
Microsoft Outlook 2007
Microsoft Windows Live Mail 2008
Microsoft Office 2007
Other products that use the Crypto API provided by Windows may also be affected.
Microsoft's Crypto API library is prone to an information-disclosure vulnerability because HTTP requests to arbitrary hosts and ports may be automatically triggered when validating X.509 certificates.
Successful exploits allow attackers to trigger HTTP requests to arbitrary hosts and ports without confirmation or notification to unsuspecting users. Attackers may use this for determining when email and documents are read, for port scanning, or for aiding in other attacks.
The following products are known to exhibit this issue:
Microsoft Outlook 2007
Microsoft Windows Live Mail 2008
Microsoft Office 2007
Other products that use the Crypto API provided by Windows may also be affected.
Exploit / POC
Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability
The following Office document will trigger HTTP requests to an external webserver.
The referenced advisories also state that sending a blank email to <[email protected]> will result in a reply email that is S/MIME-encoded in a manner that also triggers the issue.
Symantec has not validated the safety of the document or email, so users should take appropriate precautions for handling potentially malicious content.
The following Office document will trigger HTTP requests to an external webserver.
The referenced advisories also state that sending a blank email to <[email protected]> will result in a reply email that is S/MIME-encoded in a manner that also triggers the issue.
Symantec has not validated the safety of the document or email, so users should take appropriate precautions for handling potentially malicious content.
Solution / Fix
Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability
References:
References:
- Microsoft Office Product Homepage (Microsoft)
- Unauthorized reading confirmation from Outlook ("Augusto Paes de Barros"
) - Security Advisory AKLINK-SA-2008-002 (Alexander Klink)
- Security Advisory AKLINK-SA-2008-003 (Alexander Klink)
- Security Advisory AKLINK-SA-2008-004 (Alexander Klink)