vendor:
Microsoft Outlook Express, Windows Mail
by:
Francis Provencher (Protek Research Lab's)
7.5
CVSS
HIGH
Remote Code Execution
Unknown
CWE
Product Name: Microsoft Outlook Express, Windows Mail
Affected Version From: Windows 2000
Affected Version To: Windows Server 2008 SR2
Patch Exists: YES
Related CWE: CVE-2010-0816
CPE: o:microsoft:windows
Platforms Tested: Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008 SR2
2010
Vulnerability in Microsoft Outlook Express and Windows Mail
An unauthenticated remote code execution vulnerability exists in the way that the Windows Mail Client handles certain email messages. This vulnerability allows an attacker to execute arbitrary code on the target system.
Mitigation:
Apply the latest security updates from Microsoft to address this vulnerability.