The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS01-038 : Outlook View Control Exposes Unsafe Functionality
Time: 00:01 EST/05:01 GMT | News Source: Microsoft TechNet Security | Posted By: Robert Stein

The Microsoft Outlook View Control is an ActiveX control that allows Outlook mail folders to be viewed via web pages. The control should only allow passive operations such as viewing mail or calendar data. In reality, though, it exposes a function that could allow the web page to manipulate Outlook data. This could enable an attacker to delete mail, change calendar information, or take virtually any other action through Outlook including running arbitrary code on the user's machine. Hostile web sites would pose the greatest threat with respect to this vulnerability. If a user could be enticed into visiting a web page controlled by an attacker, script or HTML on the page could invoke the control when the page was opened. The script or HTML could then use the control to take whatever action the attacker desired on the user's Outlook data.

It also would be possible for the attacker to send an HTML e-mail to a user, with the intent of invoking the control when the recipient opened the mail. However, the Outlook E-mail Security Update, that automatically installs as part of Outlook 2002 would thwart such an attack. The Update causes HTML e-mails to be opened in the Restricted Sites Zone, where ActiveX controls are disabled by default. Microsoft is preparing a patch that will eliminate the vulnerability. However, while this patch is under development, we recommend that customers disable ActiveX controls in the Internet Zone to protect against the web-based scenario discussed above. (The FAQ provides information on how administrators can use Group Policy to make this configuration change network-wide). To protect against the mail-borne scenario, we strongly recommend that Outlook 98 and 2000 users install the Outlook E-mail Security Update if they haven’t already done so. When the patch is complete, Microsoft will re-release this bulletin and provide details on where to obtain the patch and how to use it.

Write Comment
Return to News

  Displaying 676 through 680 of 680
Prev | First
  The time now is 9:54:01 AM ET.
Any comment problems? E-mail us
#676 By 4240821 (45.192.45.37) at 11/10/2025 5:18:15 PM
https://www.pillowfort.social/posts/6711726
https://www.pillowfort.social/posts/6711603
https://www.pillowfort.social/posts/6711503
https://www.pillowfort.social/posts/6711417
https://www.pillowfort.social/posts/6711251
https://www.pillowfort.social/posts/6711120
https://www.pillowfort.social/posts/6710961
https://www.pillowfort.social/posts/6710770
https://www.pillowfort.social/posts/6710322
https://www.pillowfort.social/posts/6710083

#677 By 4240821 (82.115.4.230) at 11/10/2025 8:06:21 PM
https://smutty.su/activfda2bac2eb
https://sluts.su/activh1h32d23cb
https://smutty.su/activ1caeab4d4b
https://smutty.su/activ21cfb3a455
https://sexonly.su/activ2cfbfhbcch
https://sexonly.top/activ5fegacd12a
https://sexonly.su/activb43de5gb25
https://sexonly.top/activd43cfg244f
https://sexonly.su/activ52bebdd2e4
https://sexonly.top/activheb533ec2g

#678 By 4240821 (82.115.4.230) at 11/11/2025 10:32:48 AM
https://sexonly.su/activh212ahdfgb
https://lustful.su/activ51dfaaa4cc
https://sluts.su/activecfe1ah43f
https://sluts.su/activg45bhhheba
https://sluts.su/activ5ffggeha3g
https://smutty.su/activ2f2c1eeea5
https://sluts.su/activ5ehahb1c3g
https://sluts.su/activf12bc4243e
https://nsfw.su/activghbe1ab2gc
https://nsfw.su/activcdecb14e5f

#679 By 4240821 (82.115.4.230) at 11/12/2025 6:34:09 PM
https://lustful.su/activcd4345d13a
https://nsfw.su/activddf1ahg1bh
https://sexonly.top/activheaed3d4h4
https://sexonly.su/activ242gc133bd
https://sexonly.top/activdhg3hg5aeg
https://lustful.su/activbfabh4dghb
https://lustful.su/activ1fa5efh4ge
https://sexonly.top/activ32h4d54c33
https://sluts.su/activ3dga2e3h5e
https://sluts.su/activfddah4ghgc

#680 By 4240821 (82.115.4.230) at 11/13/2025 8:11:02 PM
https://sexonly.top/activ5cc2341gd2
https://nsfw.su/activdda5ghb2ga
https://sexonly.top/active4h13b5g2b
https://lustful.su/activh1hg454eed
https://lustful.su/activ1db31fc3df
https://sexonly.top/activ451haa1g42
https://sluts.su/activ5c2bbh1gbh
https://lustful.su/activ12fceb32af
https://sexonly.top/activ4bdddhaaf3
https://nsfw.su/activdeghefg52a

Write Comment
Return to News
  Displaying 676 through 680 of 680
Prev | First
  The time now is 9:54:01 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *