Home→Descriptions→SA29320
| Secunia ID | |
| CVE-ID | |
| Release Date |
11 Mar 2008 |
| Last Change |
12 Mar 2008 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
Microsoft Office 2000 |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
A vulnerability has been reported in Microsoft Outlook, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error when handling a specially crafted "mailto:" URI passed from a web browser. This can be exploited to pass extra command line switches to Outlook. Successful exploitation allows execution of arbitrary code when a user e.g. visits a malicious website. |
| Solution |
Apply patches. Outlook 2000 SP3: Outlook 2002 SP3: Outlook 2003 SP2: Outlook 2003 SP3: Outlook 2007: |
| Reported by |
Greg MacManus, iDefense Labs. |
| Original Advisory |
MS08-015 (KB949031): iDefense Labs: |