PT-2013-4703 · Microsoft · Outlook

Publicado

2013-09-11

·

Atualizado

2018-10-12

·

CVE-2013-3870

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Outlook versions 2007 SP3, 2010 SP1, 2010 SP2
Description A remote code execution issue exists due to the way Microsoft Outlook handles specially crafted S/MIME email messages. This allows attackers to execute arbitrary code by including many nested S/MIME certificates in an email message. An attacker who successfully exploits this issue could take complete control of an affected system, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Microsoft Outlook 2007 SP3, update to a version that is not affected by this issue. For Microsoft Outlook 2010 SP1, update to a version that is not affected by this issue. For Microsoft Outlook 2010 SP2, update to a version that is not affected by this issue.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3870

Produtos afetados

Outlook