MS04-013 needs revision?

G

Guest

Currently we have system that are being compromised with the
MHTMLRedir.Exploit (Symantec) which is supposedly patched with MS04-013.
However the MS04-013 article clearly states that this article is to be read
by customers with Microsoft Outlook Express installed. None of our systems
run or are installed with Outlook Express, and so the patch was never
applied, but yet the compromise is still possible. It seems that this is
just a problem of wording and language within the article that needs to be
revised. Unfortunately it is too late for us, but hopefully others will
apply this patch to systems not running OE.

this example will actually try to compromise your system so beware (you need
to have the patch installed and an updated AV engine running on your
workstation to be spared):
1. Go to www.fun-photo.com
2. Click on "Most Viewed"
3. welcome to my hell
 
P

PA Bear

...None of our systems run or are installed with Outlook Express,
and so the patch was never applied...

And did you read?...

<QP>
What systems are primarily at risk from the vulnerability?

**By default, Outlook Express is installed on all supported Windows
systems**...

I do not use Outlook Express to read e-mail or newsgroups. Am I at risk from
this vulnerability?

Yes. Because Outlook Express is installed by default, customers will be at
risk until this update is applied. An attacker could exploit this
vulnerability through a **malicious Web site** or through HTML e-mail,
regardless of whether Outlook Express is the default e-mail reader.
</QP>
Source: http://www.microsoft.com/technet/security/bulletin/MS04-013.mspx

I suggest you install MS04-013 or a newer Cumulative Security Update for
Outlook Express (e.g., MS04-018, MS05-030), as appopriate for each OS.
 
G

Guest

Yes I read the entire article *after* the incident. I still think the
language could be improved and the intended audience is misleading. Again,
our desktops never have OE not even from their initial install, so the
impression was that it did not apply. If the intended audience for an
article is SMS users and we do not have it implemented, chances are I'm not
going to read the article...
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top