PT-2008-1765 · Microsoft · Office Xp+3

Greg Macmanus

·

Publicado

2008-03-11

·

Atualizado

2018-10-12

·

CVE-2008-0110

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Outlook in Office versions prior to the fixed version
Description The issue allows remote code execution if a specially crafted mailto URI is passed to Outlook. This could enable an attacker to install programs, view, change, or delete data, or create new accounts with full user rights. Users with fewer user rights on the system may be less impacted than those operating with administrative user rights.
Recommendations For Microsoft Outlook in Office 2000 SP3, update to a version that includes the fix for this issue. For Microsoft Outlook in Office XP SP3, update to a version that includes the fix for this issue. For Microsoft Outlook in Office 2003 SP2 and SP3, update to a version that includes the fix for this issue. As a temporary workaround, consider avoiding the use of crafted mailto URIs in Outlook until a patch is available.

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0110

Produtos afetados

Outlook
Office 2000
Office 2003
Office Xp