Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Windows : Microsoft Bulletins >> Cumulative Security Update for Outlook Express (923694)


Vulnerability Assessment Details

Cumulative Security Update for Outlook Express (923694)

Vulnerability Assessment Summary
Acertains the presence of update 923694

Detailed Explanation for this Vulnerability Assessment

Summary :

Arbitrary code can be executed on the remote host through the email
client.

Description:

The remote host is running a version of Microsoft Outlook Express
which contains a security flaw which may permit a possible hacker to execute
arbitrary code on the remote host.

To exploit this flaw, a possible hacker would need to send a malformed HTML
email to a victim on the remote host and have him open it.

Solution :

Microsoft has released a set of patches for Outlook Express :

See: http://www.microsoft.com/technet/security/bulletin/ms06-076.mspx

Network Security Threat Level:

Medium / CVSS Base Score : 5.6
(AV:R/AC:H/Au:NR/C:P/I:P/A:P/B:N)

Networks Security ID: 21501

Vulnerability Assessment Copyright: This script is Copyright (C) 2006 Tenable Network Security

Wireless Networking, WiFi

Discussions

No Discussions have been posted on this vulnerability.