Denial of Service in Microsoft Outlook Express

A Denial of Service (DoS) condition exists in Microsoft Outlook Express, which ships with all versions of Windows.

Ken Pfeil

July 17, 2004

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported July 13, 2004, byMicrosoft

VERSIONS AFFECTED

DESCRIPTION
A Denial of Service (DoS) condition exists in Microsoft Outlook Express, which shipswith all versions of Windows. This vulnerability is a result of a lack ofrobust verification for malformed email headers. A potential attacker couldexploit this condition by sending a specially crafted email with malformedheaders, thereby causing Outlook Express to fail. If the preview pane isenabled, the user would have to manually remove the message, then restartOutlook Express to resume functionality.

VENDOR RESPONSE
Microsoft has releasedbulletin MS04-018, "Cumulative Security Update for OutlookExpress (823353)," to address this vulnerability and recommends thataffected users apply the appropriate patch listed in the bulletin. Thisbulletin supersedes MS04-013.

CREDIT
Discovered by Microsoft.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like