Short Name |
SMTP:URL-LOC |
---|---|
Severity |
Medium |
Recommended |
No |
Recommended Action |
Drop |
Category |
SMTP |
Keywords |
URL With Local Reference |
Release Date |
2007/04/02 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against Windows Mail Client. Versions running on Windows Vista are vulnerable. Attackers can execute code in the context of the user logged in.
Microsoft Windows Vista Windows Mail is prone to a local file-execution vulnerability due to a design error. An attackers may exploit this issue to execute local files. The attacker must entice a victim into opening a maliciously crafted link using the affected application. The vendor reports this issue can also be exploited through use of UNC navigation to execute arbitrary remote code. This may facilitate a remote compromise of the affected computer.