Microsoft Outlook Express and Windows Mail Integer Overflow Vulnerability( 12 May 2010 )
RISK: Medium Risk
An unauthenticated remote code execution vulnerability exists in the way that Windows Mail Client handles specially crafted mail responses. An attempt to exploit the vulnerability would not require authentication, allowing an attacker to exploit the vulnerability by sending a specially crafted response to a client initiating a connection to a server under his control using the common mail protocols POP3 and IMAP.
Impact
- Remote Code Execution
System / Technologies affected
- Microsoft Windows 2000
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
- Windows 7
- Microsoft Outlook Express 5.5
- Microsoft Outlook Express 6
- Windows Mail
- Windows Live Mail
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Download locations for this patch
- Microsoft Windows 2000 Service Pack 4
- Microsoft Outlook Express 5.5 Service Pack 2
- Microsoft Outlook Express 6 Service Pack 1 - Windows XP Service Pack 2 and Windows XP Service Pack 3
- Microsoft Outlook Express 6
- Windows Live Mail - Windows XP Professional x64 Edition Service Pack 2
- Microsoft Outlook Express 6
- Windows Live Mail - Windows Server 2003 Service Pack 2
- Microsoft Outlook Express 6 - Windows Server 2003 x64 Edition Service Pack 2
- Microsoft Outlook Express 6 - Windows Server 2003 with SP2 for Itanium-based Systems
- Microsoft Outlook Express 6 - Windows Vista Service Pack 1 and Windows Vista Service Pack 2
- Windows Mail
- Windows Live Mail - Windows Vista x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2
- Windows Mail
- Windows Live Mail - Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Mail
- Windows Live Mail - Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Mail
- Windows Live Mail - Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
- Windows Mail
- Windows Live Mail - Windows 7 for 32-bit Systems
- Windows Mail
- Windows Live Mail - Windows 7 for x64-based Systems
- Windows Mail
- Windows Live Mail - Windows Server 2008 R2 for x64-based Systems
- Windows Mail
- Windows Live Mail - Windows Server 2008 R2 for Itanium-based Systems
- Windows Mail
- Windows Live Mail
Vulnerability Identifier
Source
Related Link
Share with