Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-2055

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2006-2055
Last Modified 07 Mar 2011 09:35:05
Published 26 Apr 2006 04:06:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-2055

Summary

Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.

Vulnerable Systems

Application

  • Microsoft Outlook 2003


References

XF - office-mailto-obtain-information(26118)

VUPEN - ADV-2006-1538

OSVDB - 25003

SECUNIA - 19819

MISC - http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html


Last Updated: 27 May 2016 10:42:19