![]() |
SharePoint Web Parts | Office 365 Web Parts | Support | Search | About us | Home |
| News | Go back |
Security flaw reported in MS Outlook Thursday, April 25, 2002 Outlook 2000 and 2002 provide the option to use Microsoft Word as the e-mail editor when creating and editing e-mail in either Rich-Text or HTML format. A security vulnerability exists when Outlook is configured this way and the user forwards or replies to a mail from an attacker. An attacker could exploit this vulnerability by sending a specially malformed HTML e-mail containing a script to an Outlook user who has Word enabled as the e-mail editor. If the user replied to or forwarded the e-mail, the script would then run, and be capable of taking any action the user could take. More infos: http://www.microsoft.com/technet/security/bulletin/MS02-021.asp Author: Site Admin ![]() |