Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Microsoft Outlook vulnerability could allow remote code execution


Report ID: MS201309002
Date Published: 11 September 2013

Criticality: Critical
Compromise Type: remote-code-execution
Compromise From: remote


Affected Product/Component:

Microsoft Outlook 2007
Microsoft Outlook 2010




Summary

A vulnerability in Microsoft Outlook could allow an attacker to execute arbitrary code on an affected system.



Detailed Description

Microsoft has released a security update for Microsoft Outlook to address a vulnerability caused by improper parsing of the contents of an S/MIME message. An attacker who successfully exploited the vulnerability could be able to execute code and take control of an affected system.

The vulnerability has been addressed in the latest update by correcting the way that S/MIME email messages are parsed. Users are recommended to install the update to their system as a protection measure against exploit attempts.



CVE Reference

CVE-2013-3870



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms13-068)



Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.