Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/312910 | mailing list exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11411 | vdb entry |
http://www.securityfocus.com/bid/6923 | vdb entry exploit |
http://www.securityfocus.com/archive/1/312929 | mailing list |