about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability


Title Microsoft Crypto API X.509 Certificate Validation Remote Information Disclosure Vulnerability
Published 2008-04-01-12:00AM
Updated 2008-07-04-07:00PM
Class Design Error
CVE  
Remote  Yes
Local  No
Credit  Alexander Klink
Vulnerable  Microsoft Windows Live Mail 2008 0
Microsoft Outlook 2007 0
Microsoft Office 2007 SP1
Microsoft Office 2007 0
Microsoft Access 2007 0
Microsoft Access 2007 0
Microsoft Excel 2003
Microsoft Excel 2007 0
Microsoft Excel 2007 0
Microsoft FrontPage 2003
Microsoft Groove 2007 0
Microsoft Groove 2007 0
Microsoft InfoPath 2003
Microsoft InfoPath 2007 0
Microsoft InfoPath 2007 0
Microsoft Office Communicator 2007 0
Microsoft Office Communicator 2007 0
Microsoft OneNote 2003 0
Microsoft Outlook 2003 0
Microsoft Outlook 2007 0
Microsoft Outlook 2007 0
Microsoft PowerPoint 2003 0
Microsoft PowerPoint 2007 0
Microsoft PowerPoint 2007 0
Microsoft Project Professional 2007 0
Microsoft Project Professional 2007 0
Microsoft Project Standard 2007 0
Microsoft Project Standard 2007 0
Microsoft Publisher 2003
Microsoft Publisher 2007 0
Microsoft Publisher 2007 0
Microsoft SharePoint Designer 2007 0
Microsoft SharePoint Designer 2007 0
Microsoft Visio Professional 2007 0
Microsoft Visio Professional 2007 0
Microsoft Visio Standard 2007 0
Microsoft Visio Standard 2007 0
Microsoft Crypto API 0
Not Vulnerable  
Code  The following Office document will trigger HTTP requests to an external webserver.The referenced advisories also state that sending a blank email to <smime-http@klink.name> will result in a reply email that is S/MIME-encoded in a manner that also triggers the issue.Symantec has not validated the safety of the document or email, so users should take appropriate precautions for handling potentially malicious content.
  • /data/vulnerabilities/exploits/HTTP_over_Office_2007_PoC.docx
  • TXT  t3xt 1t!


    Advertising

    Copyright 2007, SecurityDot
    Sat, 22 Nov 2008 22:58:09 +0000

    Friends : milw0rm.com , secunia.com , securityfocus.com
    GOOGLE
    NEWS EXPLOITS VULNS
    exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
    i.../31377 xxxpechtv. free photo t298t pinchunter Bokp indo sex maroc. 10.20.30.t www.geteen /board/kbo 2.6.9-023 sex girls .asp tokyosex www.pornor Animail se P...Foptio www.youtob phphtml.ph ms06-077 dwl-g132 200+/compo Www.17 ABG bdir.htr carlcomms wwwporno.c Www.my+sex Foto bugil Fedora 5 www.zoopor sseyx MEN film sexs Linux Kern Ww.indian botnet mambo Remo master.pas for sania CMS is Fre t174t singer imtoo 3gp sex girls Hindi movi www. iranx Www+xxx+na gaypics DRESS Buffer Ove