Code Execution Vulnerability in Microsoft Outlook 2002

A vulnerability in Outlook 2002 can result in the execution of arbitrary code on the vulnerable system.

Ken Pfeil

March 10, 2004

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported March 9, 2004, by Microsoft.

 

 

 

VERSIONS AFFECTED

 

·        Microsoft Office XP Service Pack 2 (SP2)

·        Microsoft Office Outlook 2002 SP2

 

DESCRIPTION

 

A vulnerability in Outlook 2002 can result in the execution of arbitrary code on the vulnerable system, under the Local Computer Zone. The parsing of specially crafted mailto URLs by Outlook 2002 causes this vulnerability.

 

VENDOR RESPONSE

 

Microsoft has released security bulletinMS04-009, "Vulnerability in Microsoft Outlook Could Allow Code Execution (828040)," to address this vulnerability and recommends that affected users immediately apply the appropriate patch listed in the bulletin.

 

CREDIT

 

Discovered byiDefense andJouko Pynnönen.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like