Microsoft Outlook Express Arbitrary Program Execution Vulnerability
BID:9673
Info
Microsoft Outlook Express Arbitrary Program Execution Vulnerability
| Bugtraq ID: | 9673 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 16 2004 12:00AM |
| Updated: | Feb 16 2004 12:00AM |
| Credit: | The disclosure of this issue has been credited to <[email protected]>. |
| Vulnerable: |
Microsoft Outlook Express 5.0.1 Microsoft Outlook Express 4.72.3612 Microsoft Outlook Express 4.72.3120 Microsoft Outlook Express 4.72.2106 Microsoft Outlook Express 4.27.3110 Microsoft Outlook Express 4.0.1 SP2 Microsoft Outlook Express 6.0 Microsoft Outlook Express 5.5 Microsoft Outlook Express 5.0 Microsoft Outlook Express 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Outlook Express Arbitrary Program Execution Vulnerability
It has been reported that Microsoft Outlook Express may be prone to a vulnerability that may allow an attacker to execute arbitrary applications on a vulnerable system.
Due to a lack of information, further details are not available at the moment. This BID will be updated as more information becomes available. This issue may be related to the vulnerability described as Microsoft Outlook and Outlook Express Arbitrary Program Execution Vulnerability (BID 6923).
It has been reported that Microsoft Outlook Express may be prone to a vulnerability that may allow an attacker to execute arbitrary applications on a vulnerable system.
Due to a lack of information, further details are not available at the moment. This BID will be updated as more information becomes available. This issue may be related to the vulnerability described as Microsoft Outlook and Outlook Express Arbitrary Program Execution Vulnerability (BID 6923).
Exploit / POC
Microsoft Outlook Express Arbitrary Program Execution Vulnerability
Proof of concept can be found in the attached message reference.
Proof of concept can be found in the attached message reference.
Solution / Fix
Microsoft Outlook Express Arbitrary Program Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.