SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#393305

Microsoft Office mailto URI remote code execution

Overview

A vulnerability in the way that Microsoft Outlook handles a certain type of hyperlink could allow a remote attacker to execute arbitrary code on the vulnerable system.

I. Description

Microsoft Outlook provides a centralized application for managing and organizing e-mail messages, schedules, tasks, notes, contacts, and other information. Outlook is included as a component of newer versions of Microsoft Office and available as a stand-alone product.

Outlook exposes a vulnerability due to inadequate checking of parameters passed to the Outlook email client. The vulnerability is caused due to the manner in which Outlook interprest a mailto: URI. By creating a specially formatted mailto: URI, an attacker may be able to alter the way that Outlook is invoked in order to allow code execution. The malicious code could be delivered to the victim via a specially-crafted HTML email message or from a webpage controlled by the attacker.

II. Impact

Successful exploitation of this vulnerability could allow a remote, unauthenticated attacker to execute arbitrary code. Upon successful exploitation, the malicious code would be executed in the context of the "Local Machine" under the user running Outlook.

III. Solution

Apply Update

Microsoft has addressed this vulnerability in Microsoft Security Bulletin MS08-015.

Workaround

As stated directly from MS08-015:

    Disabling the mailto handler in the system registry key helps protect affected systems from attempts to exploit this vulnerability.

Systems Affected

VendorStatusDate Updated
Microsoft CorporationVulnerable11-Mar-2008

References


http://www.microsoft.com/technet/security/bulletin/ms08-015.mspx
http://blogs.technet.com/swi/archive/2008/03/11/protocol-handler-and-its-default-security-zone.aspx

Credit

Microsoft acknowledges Greg MacManus of iDefense Labs for reporting this vulnerability.

This document was written by Joseph W. Pruszynski.

Other Information

Date Public03/11/2008
Date First Published03/11/2008 04:52:10 PM
Date Last Updated04/01/2008
CERT Advisory 
CVE NameCVE-2008-0110
US-CERT Technical Alerts 
Metric26.32
Document Revision25

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2008 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader