Short Name |
HTTP:STC:OUTLOOK:SHELL-PROFILE |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
microsoft outlook ouchlook shell |
Release Date |
2004/05/12 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects a malicious link contained in a HTML document. Microsoft Outlook 2003 is vulnerable; other Outlook versions can also be affected. Attackers can embed a maliciously crafted link in an HTML document; when the HTML document is viewed, the link executes a file in the local user profile directory.
Microsoft Outlook and Outlook Express are reported to be prone to store various files, which may contain attacker-supplied content, in predictable locations. This may present a security risk because many known (and potential) Internet Explorer vulnerabilities depend on the attacker being able to directly reference malicious content on a victim system. Given both the ability to place such content on the file system and reference it specifically by location, exploitation of many browser-based vulnerabilities becomes possible. Other securiy consequences also exist, such as disclosure of Address Book contents.