PT-2004-3374 · Microsoft · Outlook+1
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2482
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Microsoft Outlook versions 2000 through 2003
Description:
The issue occurs when Microsoft Outlook is configured to use Microsoft Word as the e-mail editor and the user forwards an e-mail. It fails to properly handle an opening OBJECT tag without a corresponding closing OBJECT tag. This causes Outlook to automatically download the URI specified in the
data property of the OBJECT tag, potentially allowing remote attackers to execute arbitrary code.Recommendations:
For Microsoft Outlook versions 2000 through 2003, consider disabling the use of Microsoft Word as the e-mail editor until a fix is available. As a temporary workaround, avoid forwarding e-mails that may contain malicious OBJECT tags.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Outlook
Office Word