Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

SMTP:URL-LOC

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

SMTP

Keywords

URL With Local Reference

Release Date

2007/04/02

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

SMTP: URL With Local Reference


This signature detects attempts to exploit a known vulnerability against Windows Mail Client. Versions running on Windows Vista are vulnerable. Attackers can execute code in the context of the user logged in.

Extended Description

Microsoft Windows Vista Windows Mail is prone to a local file-execution vulnerability due to a design error. An attackers may exploit this issue to execute local files. The attacker must entice a victim into opening a maliciously crafted link using the affected application. The vendor reports this issue can also be exploited through use of UNC navigation to execute arbitrary remote code. This may facilitate a remote compromise of the affected computer.

Affected Products

  • Microsoft Windows Mail
  • Microsoft Windows Vista Business
  • Microsoft Windows Vista Enterprise
  • Microsoft Windows Vista Home Basic
  • Microsoft Windows Vista Home Premium
  • Microsoft Windows Vista Ultimate

References

  • BugTraq: 23103
  • CVE: CVE-2007-1658
  • URL: http://securitytracker.com/alerts/2007/Mar/1017816.html
  • URL: http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053143.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out