Microsoft Outlook TNEF Stream With MAPI Attachment Remote Code Execution Vulnerability
BID:41446
Info
Microsoft Outlook TNEF Stream With MAPI Attachment Remote Code Execution Vulnerability
| Bugtraq ID: | 41446 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2010-0266 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2010 12:00AM |
| Updated: | Aug 16 2010 05:04PM |
| Credit: | Yorick Koster, working with the SSD/SecuriTeam Secure Disclosure program |
| Vulnerable: |
Microsoft Outlook 2007 SP2 0 Microsoft Outlook 2007 SP1 0 Microsoft Outlook 2007 0 Microsoft Outlook 2003 SP3 Microsoft Outlook 2003 SP2 Microsoft Outlook 2003 0 Microsoft Outlook 2002 SP3 Microsoft Outlook 2002 SP2 Microsoft Outlook 2002 SP1 Microsoft Outlook 2002 0 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook TNEF Stream With MAPI Attachment Remote Code Execution Vulnerability
Microsoft Outlook is prone to a remote code-execution vulnerability because it fails to properly verify attachments.
Attackers can exploit this issue by enticing an unsuspecting user into opening a specially crafted email attachment.
Successfully exploiting this issue will allow an attacker to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts will result in a denial-of-service condition.
Microsoft Outlook is prone to a remote code-execution vulnerability because it fails to properly verify attachments.
Attackers can exploit this issue by enticing an unsuspecting user into opening a specially crafted email attachment.
Successfully exploiting this issue will allow an attacker to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft Outlook TNEF Stream With MAPI Attachment Remote Code Execution Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Attackers can exploit this issue with readily available tools.
The following exploit codes are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Attackers can exploit this issue with readily available tools.
The following exploit codes are available:
Solution / Fix
Microsoft Outlook TNEF Stream With MAPI Attachment Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft Outlook 2007 SP2 0
Microsoft Outlook 2007 SP1 0
Microsoft Outlook 2003 SP3
Microsoft Outlook 2002 SP3
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Microsoft Outlook 2007 SP2 0
-
Microsoft Security Update for Microsoft Office Outlook 2007 (KB980376)
http://www.microsoft.com/downloads/details.aspx?familyid=4E2E7C49-6665 -4135-ADBB-8E831A91D0FE
Microsoft Outlook 2007 SP1 0
-
Microsoft Security Update for Microsoft Office Outlook 2007 (KB980376)
http://www.microsoft.com/downloads/details.aspx?familyid=4E2E7C49-6665 -4135-ADBB-8E831A91D0FE
Microsoft Outlook 2003 SP3
-
Microsoft Security Update for Microsoft Office Outlook 2003 (KB980373)
http://www.microsoft.com/downloads/details.aspx?familyid=EF5B0048-96F1 -43A6-9848-7F6ADCCD10B3
Microsoft Outlook 2002 SP3
-
Microsoft Security Update for Microsoft Outlook 2002 (KB980371)
http://www.microsoft.com/downloads/details.aspx?familyid=DAACF400-4AA3 -4479-A60F-B8863BA1E16D
References
Microsoft Outlook TNEF Stream With MAPI Attachment Remote Code Execution Vulnerability
References:
References:
- Microsoft Outlook Homepage (Microsoft )
- MS10-045: Microsoft Office Outlook Remote Code Execution vulnerability (Microsoft Security Research and Defense)
- Outlook PR_ATTACH_METHOD file execution vulnerability (Akita Software Security)
- Microsoft Security Bulletin MS10-045 (Microsoft)