Microsoft Outlook / Microsoft Exchange TNEF Decoding Remote Code Execution Vulnerability

Microsoft Exchange Server and Outlook email clients are prone to a remote code-execution vulnerability.

This vulnerability presents itself when the applications decode a message containing a specially crafted TNEF MIME attachment. Successful exploitation may result in arbitrary code execution facilitating a remote compromise.

An attack against Microsoft Exchange Server could lead to a SYSTEM-level remote compromise, while attacks against Outlook would result in arbitrary code execution in the context of the current user.


 

Privacy Statement
Copyright 2010, SecurityFocus