Microsoft Outlook Express And Windows Mail MHTML Handler Information Disclosure Vulnerability
BID:30585
Info
Microsoft Outlook Express And Windows Mail MHTML Handler Information Disclosure Vulnerability
| Bugtraq ID: | 30585 |
| Class: | Design Error |
| CVE: |
CVE-2008-1448 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2008 12:00AM |
| Updated: | Aug 25 2008 03:35PM |
| Credit: | Jorge Luis Alvarez Medina |
| Vulnerable: |
Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP3 Microsoft Windows XP Professional SP2 Microsoft Windows Vista x64 Edition SP1 Microsoft Windows Vista x64 Edition 0 Microsoft Windows Vista SP1 Microsoft Windows Vista 0 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Standard x64 Edition Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Itanium SP1 Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Microsoft Windows Mail 0 Microsoft Windows 2000 Professional SP4 Microsoft Outlook Express 6.0 SP1 Microsoft Outlook Express 6.0 Microsoft Outlook Express 5.5 SP2 HP Storage Management Appliance III HP Storage Management Appliance II HP Storage Management Appliance I HP Storage Management Appliance 2.1 HP Storage Management Appliance 2.1 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Express And Windows Mail MHTML Handler Information Disclosure Vulnerability
Microsoft Outlook Express And Windows Mail are prone to an information-disclosure vulnerability because of an error in the Windows MHTML protocol handler.
Note that an attacker can exploit this issue via Internet Explorer because the browser internally uses the vulnerable component of Outlook Express and Windows Mail. Successful exploits will allow the attacker to bypass Internet Explorer domain restrictions and to read data from a different Internet Explorer domain or security zone.
Microsoft Outlook Express And Windows Mail are prone to an information-disclosure vulnerability because of an error in the Windows MHTML protocol handler.
Note that an attacker can exploit this issue via Internet Explorer because the browser internally uses the vulnerable component of Outlook Express and Windows Mail. Successful exploits will allow the attacker to bypass Internet Explorer domain restrictions and to read data from a different Internet Explorer domain or security zone.
Exploit / POC
Microsoft Outlook Express And Windows Mail MHTML Handler Information Disclosure Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
Solution / Fix
Microsoft Outlook Express And Windows Mail MHTML Handler Information Disclosure Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows Vista SP1
Microsoft Windows Server 2008 for x64-based Systems 0
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003 Itanium SP1
Microsoft Windows XP Professional x64 Edition SP2
Microsoft Windows Server 2008 for Itanium-based Systems 0
Microsoft Windows XP Professional SP3
Microsoft Windows Server 2008 for 32-bit Systems 0
Microsoft Windows Vista x64 Edition 0
Microsoft Windows Server 2003 SP2
Microsoft Windows XP Professional SP2
Microsoft Windows Vista 0
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows Server 2003 Standard x64 Edition
Microsoft Windows Vista x64 Edition SP1
Microsoft Windows 2000 Professional SP4
Microsoft Windows Server 2003 SP1
Solution:
The vendor has released fixes. Please see the references for more information.
Microsoft Windows Server 2003 Itanium SP2
-
Microsoft Security Update for Outlook Express for Windows Server 2003 for Itanium-based Systems (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c8570e40-355b -4a9b-933d-53ae021cbda5&displaylang=en
Microsoft Windows Vista SP1
-
Microsoft Security Update for Windows Mail for Windows Vista (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=3851bcf8-f971 -4d38-b27f-97396854aac0&displaylang=en
Microsoft Windows Server 2008 for x64-based Systems 0
-
Microsoft Security Update for Windows Mail for Windows Server 2008 x64 Edition (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5f973f54-2322 -4b41-8c1a-3e712c0da8ae&displaylang=en
Microsoft Windows XP Professional x64 Edition
-
Microsoft Security Update for Outlook Express for Windows XP x64 Edition (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=2220aece-79d2 -426f-90ec-24a17470567a&displaylang=en
Microsoft Windows Server 2003 Itanium SP1
-
Microsoft Security Update for Outlook Express for Windows Server 2003 for Itanium-based Systems (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c8570e40-355b -4a9b-933d-53ae021cbda5&displaylang=en
Microsoft Windows XP Professional x64 Edition SP2
-
Microsoft Security Update for Outlook Express for Windows XP x64 Edition (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=2220aece-79d2 -426f-90ec-24a17470567a&displaylang=en
Microsoft Windows Server 2008 for Itanium-based Systems 0
-
Microsoft Security Update for Windows Mail for Windows Server 2008 for Itanium-based Systems (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=9226cd85-1445 -4976-a126-757c5d142ffd&displaylang=en
Microsoft Windows XP Professional SP3
-
Microsoft Security Update for Outlook Express for Windows XP (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=91469f2f-461c -4a67-8738-d42520427f6b&displaylang=en
Microsoft Windows Server 2008 for 32-bit Systems 0
-
Microsoft Security Update for Windows Mail for Windows Server 2008 (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=dc3c4b63-acd3 -4469-8d47-e0562d99ee65&displaylang=en
Microsoft Windows Vista x64 Edition 0
-
Microsoft Security Update for Windows Mail for Windows Vista for x64-based Systems (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=3bf7eb8a-b347 -4661-be2d-682adc713769&displaylang=en
Microsoft Windows Server 2003 SP2
-
Microsoft Security Update for Outlook Express for Windows Server 2003 (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=30f2244a-f6fd -4fc1-a871-abf6958cb660&displaylang=en
Microsoft Windows XP Professional SP2
-
Microsoft Security Update for Outlook Express for Windows XP (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=91469f2f-461c -4a67-8738-d42520427f6b&displaylang=en
Microsoft Windows Vista 0
-
Microsoft Security Update for Windows Mail for Windows Vista (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=3851bcf8-f971 -4d38-b27f-97396854aac0&displaylang=en
Microsoft Windows Server 2003 x64 SP2
-
Microsoft Security Update for Outlook Express for Windows Server 2003 x64 Edition (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=3287f006-cbb2 -4c6d-820c-32833e08035a&displaylang=en
Microsoft Windows Server 2003 Standard x64 Edition
-
Microsoft Security Update for Outlook Express for Windows Server 2003 x64 Edition (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=3287f006-cbb2 -4c6d-820c-32833e08035a&displaylang=en
Microsoft Windows Vista x64 Edition SP1
-
Microsoft Security Update for Windows Mail for Windows Vista for x64-based Systems (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=3bf7eb8a-b347 -4661-be2d-682adc713769&displaylang=en
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Outlook Express 5.5 Service Pack 2 (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=6257bfae-35f0 -4c0e-b960-bca7aa6f86f7&displaylang=en -
Microsoft Security Update for Outlook Express 6 Service Pack 1 (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=dab178f7-c282 -41f4-acb1-a86e6aa4c91b&displaylang=en
Microsoft Windows Server 2003 SP1
-
Microsoft Security Update for Outlook Express for Windows Server 2003 (KB951066)
http://www.microsoft.com/downloads/details.aspx?FamilyId=30f2244a-f6fd -4fc1-a871-abf6958cb660&displaylang=en
References
Microsoft Outlook Express And Windows Mail MHTML Handler Information Disclosure Vulnerability
References:
References:
- Microsoft Outlook Express Homepage (Microsoft)
- Windows Mail Product Page (Microsoft Corporation)
- CORE-2008-0103 Internet Explorer Zone Elevation Restrictions Bypass and Security (Core Security Technologies )
- Microsoft Security Bulletin MS08-048 - Important (Microsoft Corporation)