Skip to main content

Microsoft Outlook Express and Windows Mail URL Parsing Cross-Domain Information Disclosure Vulnerability( 13 August 2008 )

Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 4604 Views

RISK: Medium Risk

An information disclosure vulnerability exists in Outlook Express and Windows Mail because the MHTML protocol handler incorrectly interprets MHTML URL redirections that could potentially bypass Internet Explorer domain restrictions when returning MHTML content. An attacker could exploit the vulnerability by constructing a specially crafted Web page. If the user viewed the Web page through Internet Explorer, the vulnerability could potentially allow information disclosure. An attacker who successfully exploited this vulnerability could read data from another Internet Explorer domain or the local computer.