vendor:
Outlook Express
by:
Benjamin Tobias Franz
7.5
CVSS
HIGH
Attachment File Extension Obfuscation Vulnerability
434
CWE
Product Name: Outlook Express
Affected Version From: Microsoft Outlook Express
Affected Version To: Microsoft Outlook Express
Patch Exists: NO
Related CWE: N/A
CPE: microsoft:outlook_express
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2005
Microsoft Outlook Express Attachment File Extension Obfuscation Vulnerability
Microsoft Outlook Express is prone to an attachment file extension obfuscation vulnerability that may present a risk under certain configurations. The issue manifests due to Microsoft Outlook Express behavior while handling an 'EML' email attachment. If the email attachment does not have a filename, the subject of the attached email message is used as the filename. Reports indicate that this may be leveraged to make the attached email message executable. It is possible to cause a default file handler to be invoked to process the attached email message. Potentially allowing for code execution.
Mitigation:
Ensure that the email client is configured to block the execution of attachments with certain file extensions.