Outlook Express Flaw Elevated to Higher Risk   - 1,397 Views,

Summary: The security flaw in Outlook Express revealed by Microsoft in their June Security Bulletin, and covered by Aunty here, has taken on a new urgency as certain websites have begun sharing samples of the code required to take advantage of the security flaw. While ...

Previous Article « Survey Says! Best ISP Is…
Read Next Article » Download This, RIAA! The MP3 Toilet

  Follow Anne on Twitter


The security flaw in Outlook Express revealed by Microsoft in their June Security Bulletin, and covered by Aunty here, has taken on a new urgency as certain websites have begun sharing samples of the code required to take advantage of the security flaw.

While the flaw is still considered to be low-risk in terms of the likelihood of exploitation, it is high-risk in terms of how serious the exploitation can be if it does occur, including allowing an attacker to take complete control of the user’s computer.

In order for an attacker to gain access to the user’s computer however, the user must use Outlook Express to read Usenet newsgroups, enabling the Network News Transfer Protocol (NNTP), and further, the user must then visit a Usenet group which contains the malicious code designed to take advantage of the flaw.

Still, because the flaw and associated exploit are potentially so serious, all users with affected systems are being urged by Microsoft to update their systems here.

Outlook Express Flaw Elevated to Higher Risk

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « Survey Says! Best ISP Is…
Read Next Article » Download This, RIAA! The MP3 Toilet

Read more:

»  Windows Media and Outlook Express Both at High Risk

»  New Critical Internet Explorer (IE) Flaw Involves Msdds.dll

»  Microsoft Offers Outlook Bundled with Paid Email Service

»  No More Free Outlook Connection for Hotmail - Spammers to Blame

For additional similar stories check out our archives on Security, Windows

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 6/26/2005
The Internet Patrol
Patrolling the Internet for You!