Microsoft Outlook 'Online Mode' Remote Heap Buffer Overflow Vulnerability
BID:43063
Info
Microsoft Outlook 'Online Mode' Remote Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 43063 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-2728 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2010 12:00AM |
| Updated: | Sep 14 2010 08:12PM |
| Credit: | Dyon Balding of Secunia |
| Vulnerable: |
Microsoft Outlook 2007 SP2 0 Microsoft Outlook 2007 SP1 0 Microsoft Outlook 2007 0 Microsoft Outlook 2003 SP3 Microsoft Outlook 2003 SP2 Microsoft Outlook 2003 0 Microsoft Outlook 2002 SP3 Microsoft Outlook 2002 SP2 Microsoft Outlook 2002 SP1 Microsoft Outlook 2002 0 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook 'Online Mode' Remote Heap Buffer Overflow Vulnerability
Microsoft Outlook is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly validate user-supplied data.
Attackers can exploit this issue by enticing an unsuspecting user to preview or view a crafted email message.
Successfully exploiting this issue will allow an attacker to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts will result in a denial-of-service condition.
Microsoft Outlook is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly validate user-supplied data.
Attackers can exploit this issue by enticing an unsuspecting user to preview or view a crafted email message.
Successfully exploiting this issue will allow an attacker to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft Outlook 'Online Mode' Remote Heap Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Outlook 'Online Mode' Remote Heap Buffer Overflow Vulnerability
Solution:
Updates are available; please see the references for more information.
Microsoft Outlook 2007 SP2 0
Microsoft Outlook 2003 SP3
Microsoft Outlook 2002 SP3
Solution:
Updates are available; please see the references for more information.
Microsoft Outlook 2007 SP2 0
-
Microsoft Security Update for Microsoft Office Outlook 2007 (KB2288953)
http://www.microsoft.com/downloads/en/details.aspx?familyid=6009d507-1 35c-4ce8-a830-925134f214dc&displaylang=en
Microsoft Outlook 2003 SP3
-
Microsoft Security Update for Microsoft Office Outlook 2003 (KB2293428)
http://www.microsoft.com/downloads/en/details.aspx?familyid=ec8ed81e-0 5d0-4c20-b5fb-ebc72230a8bd&displaylang=en
Microsoft Outlook 2002 SP3
-
Microsoft Security Update for Microsoft Outlook 2002 (KB2293422)
http://www.microsoft.com/downloads/en/details.aspx?familyid=d5e85841-9 dea-4776-9e0e-3cd272066f37&displaylang=en
References
Microsoft Outlook 'Online Mode' Remote Heap Buffer Overflow Vulnerability
References:
References:
- Microsoft Outlook Homepage (Microsoft )
- Microsoft Security Bulletin MS10-064 (Microsoft)
- Secunia Research: Microsoft Outlook Content Parsing Integer Underflow Vulnerabil (Secunia)