vendor:
Outlook
by:
SecurityFocus
7.5
CVSS
HIGH
ActiveX Control
95
CWE
Product Name: Outlook
Affected Version From: Outlook XP
Affected Version To: Outlook XP
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Microsoft Outlook View Control Vulnerability
The vulnerability is due to a new ActiveX control called 'Microsoft Outlook View Control'. The flaw is that this control is marked 'safe for scripting' when it should not be. It is therefore accessible by scripts. Scripts can access and perform operations on user email through this control without user knowledge or consent.
Mitigation:
Disable ActiveX controls in Outlook or use an alternative email client.