int(2318)

Vulnerability Bulletins


Ejecución de código arbitrario en Microsoft Outlook Express

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio exotico

System information

Property Value
Affected manufacturer Microsoft
Affected software Outlook Express 5.5 <= SP2
Outlook Express 6 <= SP1

Description

Se ha descubierto una vulnerabilidad en Microsoft Outlook Express 5.5 y 6. La vulnerabilidad reside en el manejo de ficheros Windows Address Book (.wab).

Un atacante remoto podría ejecutar código arbitrario mediante un fichero .wab especialmente diseñado.

Solution



Actualización de software

Microsoft
Outlook Express 6 / Microsoft Windows Server 2003, Microsoft Windows Server 2003 SP1
http://www.microsoft.com/downloads/details.aspx?FamilyId=484DE679-5505-4196-BDD8-F7CF325AF0F5
Outlook Express 6 / Microsoft Windows Server 2003 x64 Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=A7B10D8F-D9D7-4423-AA6D-C1C41D23794E
Outlook Express 6 / Microsoft Windows Server 2003 Itanium, Microsoft Windows Server 2003 SP1 Itanium
http://www.microsoft.com/downloads/details.aspx?familyid=800BF687-BEE5-478F-A025-43CD16682F31
Outlook Express 6 / Microsoft Windows XP SP2
http://www.microsoft.com/downloads/details.aspx?FamilyId=0DD827BC-6FA1-405A-933E-FB422A4E8096
Outlook Express 6 / Microsoft Windows XP Professional x64 Edition
http://www.microsoft.com/downloads/details.aspx?familyid=FF772C0B-6F98-449D-B02E-C9C236068172
Outlook Express 6 SP1 / Microsoft Windows XP SP1, Microsoft Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?FamilyId=CDA93501-99CB-4F28-BB73-6438CAD081DB
Outlook Express 5.5 SP2 / Microsoft Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?FamilyId=E61A3D64-14FD-4976-BB03-C31CA6EE61E2

Standar resources

Property Value
CVE CVE-2006-0014
BID

Other resources

Microsoft Security Bulletin (MS06-016)
http://www.microsoft.com/technet/security/Bulletin/MS06-016.mspx

Version history

Version Comments Date
1.0 Aviso emitido 2006-04-12
Ministerio de Defensa
CNI
CCN
CCN-CERT