[NT] Microsoft Outlook Express 6 "E-mail Attachment Security" Flawed

From: support@securiteam.com
Date: 12/12/01


From: support@securiteam.com
To: list@securiteam.com
Date: Wed, 12 Dec 2001 06:59:55 +0100 (CET)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  Microsoft Outlook Express 6 "E-mail Attachment Security" Flawed
------------------------------------------------------------------------

SUMMARY

Microsoft has added a security setting to Outlook Express 6: Do not allow
attachments to be saved or opened that could potentially be a virus. This
setting is not enabled as default, but Microsoft is suggesting it in this
document entitled
<http://support.microsoft.com/default.aspx?scid=kb;EN-US;q291387> Using
Virus Protection Features in Outlook Express 6. The vulnerability lies in
the fact that forwarded mail that contain such harmful attachments, will
not be "grayed" out to discourage users from trying to open it (unlike
when reading the original message).

DETAILS

Vulnerable systems:
Outlook Express version 6.0

Vendor status:
When contacted, a person from Microsoft's Security Response Center wrote
in an e-mail: "The capability to forward an email with an attachment is a
feature in Outlook Express that is by-design. As you mention, Outlook
Express does allow the blocking of unsafe attachments.

ADDITIONAL INFORMATION

The information has been provided by <mailto:arie@infinisource.com> Arie
Slob.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Re: Suspicious email allegedly from Microsoft
    ... The attachments have different file names. ... > Microsoft never sends unsolicited files by email. ... > It is a virus masquerading as MS security. ... Microsoft Outlook, Microsoft Outlook Express, and ...
    (microsoft.public.windowsxp.security_admin)
  • Re: OE blocking incoming attachments in email
    ... Click the File Types tab. ... To disable the "Do not allow attachments to be ... saved or opened that could potentially be a virus" security feature: ... Start Outlook Express. ...
    (microsoft.public.security)
  • Multiple Infected EMails
    ... >AND the ones that look like Microsoft security notices: ... >contained another type of security threat. ... >No attachments are in this category. ... MS Outlook and MS Outlook Express as ...
    (microsoft.public.win2000.security)
  • Multiple Infected EMails
    ... >AND the ones that look like Microsoft security notices: ... >contained another type of security threat. ... >No attachments are in this category. ... MS Outlook and MS Outlook Express as ...
    (microsoft.public.win2000.security)
  • Re: OE Blocking Attachements
    ... Outlook Express' default security settings are simply trying to ... types that could potentially contain a virus. ... Tools> Options> Security, uncheck the "Do not allow attachments to ... Cannot Open E-Mail Attachments in OE After You Install SP1 ...
    (microsoft.public.windowsxp.security_admin)