vendor:
Outlook
by:
hyp3rlinx
CVSS
HIGH
Mailto Link Denial Of Service
20
CWE
Product Name: Outlook
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: a:microsoft:outlook
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2020
Microsoft Outlook VCF cards – Denial of Service (PoC)
Windows VCF cards do not properly sanitize email addresses allowing for HTML injection. A corrupt VCF card can cause all the users currently opened files and applications to be closed and their session to be terminated without requiring any accompanying attacker supplied code. This can be done by crafting the Mailto link to point to Windows 'logoff.exe'. The corrupt VCF card can then kill all users applications and also log the target off their computer, if the VCF card is opened in using Windows Contacts and the link is clicked.
Mitigation:
Microsoft has not released a patch for this vulnerability.