Outlook Express - Windows Mail - Windows Live Mail - critical vulnerability

Discussion started by MEB, May 17, 2010.

  1. MEB

    MEB Guest

    The exploit vector apparently uses inetcomm.dll vulnerabilities. Other
    vulnerabilities [per previous/other] include various other base files.

    Examples of how this vulnerability might work or could affect your
    usage would include entering/accessing a site which opens the affected
    applications via server code or page inclusion, connecting to a forum or
    news server via email or NNTP, and similar situations wherein OE, WM,
    WLM, might be used or called.


    Microsoft Security Bulletin MS10-030 - Critical
    Vulnerability in Outlook Express and Windows Mail Could Allow Remote
    Code Execution (978542)

    MS10-030: Vulnerability in Outlook Express and Windows Mail could allow
    remote code execution


    This issue comes to Win9X for a very simple reason, the base OE [and
    IE] files left/used may contain a [actually several] severe
    vulnerability{ies} which could allow the system to be taken over or
    otherwise hacked. Of course the updates offered are not compiled for use
    within Win9X since it is EOL/EOS.

    Any Win9X users that still use OE should review the prior issues and
    this present vulnerability, particularly as there is no necessity for
    elevation of privileges, or creation of new accounts. Any offered "proof
    of concept" exploits would/are designed for usage in systems which would
    require that activity [NTs] hence would likely fail in Win9X. That does
    not mean this might not still be accomplished without using the extra
    necessities for the NT based systems.

    Windows Info, Diagnostics, Security, Networking
    The "real world" of Law, Justice, and Government
    MEB, May 17, 2010
  2. If you access your account's POP3 and SMTP servers via SSL in OE (or OL),
    your computer is not subject to this vulnerability.
    PA Bear [MS MVP], May 17, 2010
  3. MEB

    Dan Guest

    Thanks for the posting MEB and thanks especially to Robear for the solution.
    Dan, May 18, 2010
  4. MEB


    Dec 22, 2010
    Likes Received:
    In all these there are several things can be possible That does
    not mean this might not still be accomplished without using the extra
    necessities for the NT based systems.
    mactilden, Dec 22, 2010
