|
|
|
![]() |
Vulnerability Note VU#131569Microsoft Outlook View Control allows execution of arbitrary code and manipulation of user dataOverviewA vulnerability exists in an ActiveX control supplied with Microsoft Outlook 2002 that could allow malicious code on a web page or in an HTML email message to manipulate Outlook data or execute arbitrary code as the user running Outlook.I. DescriptionMicrosoft Outlook 2002 installs an ActiveX control called 'Microsoft Outlook View Control'. Microsoft Outlook (and the Outlook View Control) may be installed as part of Microsoft Office. In addition, the Outlook View Control is independently available for download from Microsoft. Outlook Express is also vulnerable if the Outlook View Control is present on the system.The Outlook View Control provides access to Outlook data such as email, contacts, and calendar information. The control should provide read-only access to Outlook data, but in reality it exposes programming elements that allow the manipulation of Outlook data and, more importantly, the execution of arbitrary code with the privileges of the user running Outlook. To exploit this vulnerability, an attacker might convince a user to visit a web page or open an HTML email message containing malicious script code that invokes the control. The control is implemented in Outlook 2002 in the file OUTLCTL.DLL and independently in OUTLCTLX.DLL and is referenced by its class identifier (CLSID): 0006F063-0000-0000-C000-000000000046. Apply the appropriate patch from Microsoft. Note that these patches do not set the "kill bit" on the vulnerable ActiveX control and the control is signed by Microsoft. Depending on zone security settings, it could be possible to install a vulnerable version of the ActiveX control on a system that does not already have the control installed. To further protect against malicious code contained in email, install the Outlook Security Update and the Java Permissions Security update. Outlook 2002:
http://office.microsoft.com/downloads/2000/o2kiefrm.aspx
http://office.microsoft.com/downloads/9798/o98iefrm.aspx Disable ActiveX controls, Active scripting, and Java in the 'Internet' zone.
http://www.cert.org/tech_tips/malicious_code_FAQ.html#steps Filter Email Messages Create a client rule in Outlook 2000 or Outlook 2002 to quarantine or delete messages containing script code. Filter Script Code It may be possible to use an application layer filter to detect and block or disable script code within HTML data. Systems Affected
Referenceshttp://www.cert.org/tech_tips/malicious_code_FAQ.html#steps The CERT Coordination Center thanks Georgi Guninski, Russ Cooper of TrueSecure/NTBugTraq, and Microsoft Product Security for information used in this document. This document was written by Art Manion.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||