Advertisement
Promo

Online business Toolkit

Microsoft rushes to fix Outlook flaw

Dennis Fisher, eWeek ZDNet US

Published: 18 Jul 2001 15:59 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A vulnerability exists in Microsoft's Outlook software that could enable an attacker to easily gain control of a user's mailbox and run code or delete files.

The flaw, discovered by noted bug hunter Georgi Guninski, involves the Outlook View Control, an ActiveX component that enables users to view their mailboxes via the Web. It affects Outlook 98, 2000 and 2002, which ships with the new Office XP suite.

The View Control is only supposed to allow users to view messages or calendar entries, but an attacker need only entice a user into visiting a specially coded Web page in order to run the code to exploit the flaw, according to a bulletin released by Microsoft.

The hole could also be exploited if a user opened an HTML e-mail message containing the malicious code.

In a rare step, Microsoft issued its bulletin late last week even before it had a patch available for the problem. The patch is still under development.

In his bulletin disclosing the flaw, Guninski, who is renowned for uncovering numerous bugs in Microsoft software, listed a simple, if drastic, workaround until the patch is available: "Uninstall Office XP and Windows."

In May, Microsoft issued a bulletin warning that another ActiveX control in Outlook 2000, the office 2000 UA Control, could enable an attacker to carry out Office functions on the machine of a vulnerable user.

Microsoft is betting heavily on Office XP and the forthcoming Windows XP operating system and has stated that they will be the most secure software turned out by the company to date.

They are among the first products to hit the market since Microsoft began an in-house initiative to make security one of the centerpieces of its development process.

Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
57 out of 96 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters