News

Outlook-Word Vulnerability Could Allow Code Execution

Organizations running Microsoft's Outlook e-mail client face a new security vulnerability if some users choose Word as their default e-mail editor.

Microsoft classifies the newly discovered vulnerability as a moderate risk to client systems, and the company has a patch available at www.microsoft.com/technet/security/bulletin/MS02-021.asp.

A feature of Outlook 2000 and Outlook 2002 allows users to select Microsoft Word as the e-mail editor when writing or editing e-mail in Rich Text or HTML. A vulnerability means that when Outlook is used that way, replying or forwarding to e-mail from a malicious user could execute scripts that run in the security context of the user.

Microsoft uses different security settings for displaying e-mail versus editing e-mail. Outlook displays HTML e-mail by applying Internet Explorer security zone settings that prevent scripts from running. But if the user replies or forwards the message, Outlook opens the e-mail and passes the message to the Word editor, which doesn't block scripts.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • How To Use PowerShell Splatting

    Despite its weird name, splatting can be a really handy technique if you create a lot of PowerShell scripts.

  • New Microsoft Customer Agreement for Buying Azure Services To Start in March

    Microsoft will have a new approach for organizations buying Azure services called the "Microsoft Customer Agreement," which will be available for some customers starting as early as this March.

  • Windows 7 To Fall Out of Support in One Year

    January 14 marks a one-year period before the end of support for Windows 7.

  • CES 2019: Windows PCs Evolve for Modern Users

    Microsoft's PC partners are increasingly focused on polishing existing features to target freelancers, remote workers and creatives.

comments powered by Disqus
Most   Popular

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.