| Microsoft Outlook Zone Bypass Vulnerability Risk High |
|
|
|
Microsoft Outlook is prone to a vulnerability that may permit execution of arbitrary code on client systems. This issue is exposed through Outlook, but will reportedly cause Internet Explorer to load malicious content in the Local Zone.
This is related to how mailto URIs are handled by the software and may be exploited from a malicious web page or through HTML e-mail in situations where the Outlook Today page is the default folder home page in the client. This issue will permit a remote attacker to influence how Outlook invoked via mailto URIs, allowing for execution of malicious scripting in the Local Zone through an attacker-specified Outlook profile parameter. TNTmax recommend you upgrade your Microsoft Office XP to Servce Pack 2 SP2: Microsoft Patch MS04-009 Office XP SP2 Update |

