Re: MS04-013 needs revision?
- From: "PA Bear" <PABearMVP@xxxxxxxxx>
- Date: Fri, 5 Aug 2005 19:51:50 -0400
...None of our systems run or are installed with Outlook Express, and so the patch was never applied...
And did you read?...
<QP> What systems are primarily at risk from the vulnerability?
**By default, Outlook Express is installed on all supported Windows systems**...
I do not use Outlook Express to read e-mail or newsgroups. Am I at risk from this vulnerability?
Yes. Because Outlook Express is installed by default, customers will be at risk until this update is applied. An attacker could exploit this vulnerability through a **malicious Web site** or through HTML e-mail, regardless of whether Outlook Express is the default e-mail reader.
</QP>
Source: http://www.microsoft.com/technet/security/bulletin/MS04-013.mspx
I suggest you install MS04-013 or a newer Cumulative Security Update for Outlook Express (e.g., MS04-018, MS05-030), as appopriate for each OS.
--
~Robear Dyer (PA Bear)
MS MVP-Windows (IE/OE) & Security
Javier Sanchez wrote:
Currently we have system that are being compromised with the
MHTMLRedir.Exploit (Symantec) which is supposedly patched with MS04-013.
However the MS04-013 article clearly states that this article is to be read
by customers with Microsoft Outlook Express installed. None of our systems
run or are installed with Outlook Express, and so the patch was never
applied, but yet the compromise is still possible. It seems that this is
just a problem of wording and language within the article that needs to be
revised. Unfortunately it is too late for us, but hopefully others will
apply this patch to systems not running OE.
this example will actually try to compromise your system so beware (you need
to have the patch installed and an updated AV engine running on your
workstation to be spared):
1. Go to www.fun-photo.com
2. Click on "Most Viewed"
3. welcome to my hell
.
- Follow-Ups:
- Re: MS04-013 needs revision?
- From: Javier Sanchez
- Re: MS04-013 needs revision?
- References:
- MS04-013 needs revision?
- From: Javier Sanchez
- MS04-013 needs revision?
- Prev by Date: Re: IE 7 a high-priority update?
- Next by Date: Re: Internet Explorer 6 SP1 Setup MSI Wrapper
- Previous by thread: MS04-013 needs revision?
- Next by thread: Re: MS04-013 needs revision?
- Index(es):
Relevant Pages
|
Loading