PT-2007-1528 · Microsoft · Outlook
Published
2007-01-09
·
Updated
2018-10-16
·
CVE-2007-0033
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook versions 2002 through 2003
Description
A remote code execution issue exists when Microsoft Outlook parses a file and processes a malformed VEVENT record in an .iCal meeting request or ICS file, allowing attackers to execute arbitrary code.
Recommendations
For Microsoft Outlook versions 2002 and 2003, consider avoiding the use of .iCal meeting requests or ICS files until a fix is available.
As a temporary workaround, restrict the processing of VEVENT records in .iCal meeting requests or ICS files to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Outlook