PT-2008-3018 · Microsoft · Windows Mail+2
Published
2008-08-13
·
Updated
2018-10-12
·
CVE-2008-1448
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook Express versions 5.5 SP2 through 6 SP1
Windows Mail (affected versions not specified)
Description
The issue concerns the MHTML protocol handler in a component of Microsoft software, which fails to assign the correct Internet Explorer Security Zone to UNC share pathnames. This allows remote attackers to bypass intended access restrictions and read arbitrary files via an mhtml: URI in conjunction with a redirection.
Recommendations
For Microsoft Outlook Express versions 5.5 SP2 through 6 SP1, consider restricting access to the MHTML protocol handler until a patch is available.
For Windows Mail, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer
Outlook Express
Windows Mail