Outlook TNEF flaw could be much worse than WMF flaw

Discussion in 'Computer Support' started by Au79, Jan 13, 2006.

  1. Au79

    Au79 Guest

    by Justin Mann on Fri 13 Jan 2006, 11:11 AM

    Despite just having dealt with a very serious WMF flaw that ended up with
    users creating their own patches, it seems that IT Staffing won't get much
    of a reprieve. Critical flaws discovered in Outlook 2003, Outlook 2000,
    Exchange Server 2000, Exchange Server 5.5 and Exchange Server 5.0 could
    lead to a huge amount of compromised machines. The exploit lies in the way
    these programs handle TNEF Mime content. A particularly crafted e-mail is
    all it takes, and all an Outlook client has to do is open or preview the
    message. On the server side, when Exchange's “Information Store†processes
    the message, it can be compromised.

    "An attacker may leverage these issues to carry out a denial-of-service
    attack or execute arbitrary code on an affected computer with the
    privileges of the user viewing a malicious image," Symantec said. "An
    attacker may gain system privileges if an administrator views the malicious
    file. Local code execution may also facilitate a complete compromise."
    This could end up being a much worse case than the WMF flaw, which resulted
    in a lot of headaches and many infected machines. Apparently, this has been
    known about for close to 3 months.

    http://www.techspot.com/news/20110-outlook-tnef-flaw-could-be-much-worse-than-wmf-flaw.html

    --

    --

    http://www.vanwensveen.nl/rants/microsoft/IhateMS.html
     
    Au79, Jan 13, 2006
    #1
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. T-Bone
    Replies:
    3
    Views:
    470
    Bill McPherson
    Oct 20, 2005
  2. Au79

    MICROSOFT warns of new .wmf flaw

    Au79, Feb 10, 2006, in forum: Computer Support
    Replies:
    0
    Views:
    436
  3. x@y

    Re: It could be worse 15:

    x@y, Feb 12, 2007, in forum: Computer Support
    Replies:
    0
    Views:
    492
  4. M. Murcek

    WMF flaw patch released early...

    M. Murcek, Jan 5, 2006, in forum: Windows 64bit
    Replies:
    2
    Views:
    409
    Randy
    Jan 6, 2006
  5. thing2

    Sony's day just gets worse and worse

    thing2, Nov 23, 2005, in forum: NZ Computing
    Replies:
    27
    Views:
    1,136
    Murray Symon
    Dec 1, 2005
Loading...

Share This Page