PT-2004-1617 · Microsoft · Windows Media Player+1
Publicado
2004-06-03
·
Atualizado
2017-07-11
·
CVE-2004-0503
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook version 2003
Description
The issue allows remote attackers to bypass default zone restrictions and execute script within media files. This is achieved through a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player. The exploit bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable.
Recommendations
For Microsoft Outlook 2003, consider disabling the use of OLE objects for the Windows Media Player as a temporary workaround until a patch is available. Restrict access to media files received through email to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Outlook
Windows Media Player