NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Attackers Can Potentially Run Malicious Applications on Windows Vista

Through a client side vulnerability in Windows Mail

By Marius Oiaga, Technology News Editor

24th of March 2007, 13:13 GMT

Adjust text size:



Enlarge picture
Windows Vista is wide open to remote code execution via a flaw in Windows Mail. Designed as a successor to Outlook Express, the free email client is an integer part of Windows Vista, shipping
by default with the operating system. On March 23 2007, a client-side vulnerability allowing for remote code execution in Windows Mail was published on Full Disclosure. The report claims that the vulnerability was successfully tested on a copy of Windows Vista Ultimate.

"Remote Code Execution is possible if a user clicks on a malicious prepared link. Vistas Mail Client will execute any executable file if a folder exists with the same name. For example the victim has a folder in C: named blah and a batch script named blah.bat also in C:. Now if the victim clicks on a link in the email message with the URL target set to C: lah the batch script is executed without even asking. There is for example a CMD script by default in C:WindowsSystem32 named winrm.cmd (and also a folder named winrm inside System32)," Full Disclosure informed.

Microsoft did not confirm the validity of the vulnerability, but it did acknowledge the fact that it is investigating the issue. "As a best practice, users should always exercise extreme caution when clicking on links in unsolicited e-mail from both known and unknown sources," a Microsoft representative commented.

Considering the fact that Windows Mail is the default Mail Client in Windows Vista and that the vulnerability allows an attacker to execute and run applications on Vista machines, the flaw can be considered as impacting the operating system directly.

TAGS:

Windows Mail | Windows Vista | vulnerability
Read by 2,135 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.7/5) 9 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Windows Vista Drivers Database - No More Driver Problems!

Microsoft Will Kill Window Vista Ultimate Early

Windows Vista Power User Guide

The True Limitations of Windows Vista Virtualization

Will Apple's Leopard Bite Into Windows Vista?

Certain Versions of Windows XP Cannot Upgrade to Windows Vista

Windows Vista Support Lifecycle

Microsoft Is Touching Up Windows Vista's License

Windows Vista Brute-Force Attack Alive and Kicking

32-bit Windows Vista Eats Up RAM

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM