- Recommend:
- 0 Comments
Patching Another Outlook Security Hole
Microsoft's download will prevent hackers from using a vCard attachment to access your PC.
Microsoft has identified another security hole in its Outlook e-mail software and says a fix is available for the glitch.
The software maker last week released a patch for its Outlook and Outlook Express clients, following the identification of a hole in the software that could allow hackers to use a vCard to disable Outlook, or run code through the program.
The vCard attachment is a common way to share address book information.
This exploit, like many viruses, will work only if the user opens an infected attachment in an e-mail document. It was reported to Microsoft by Ollie Whitehouse, a British programmer.
The patch is available from Microsoft, and, as always, the company urges users to follow sound security measures, which include not opening unexpected attachments, especially from strangers.
As evidenced by the spread of the Kournikova virus earlier this month, however, users are still all too willing to open suspect attachments.
According to the Microsoft security advisory, "Outlook Express provides several components that are used both by it and, if installed on the machine, Outlook. One such component, used to process vCards, contains an unchecked buffer."
A buffer temporarily stores data in devices or software. Programmers can design buffers to check the size of data entered into them and reject entries that are too long. When they are "unchecked," it means there is no such safeguard, and users can enter any amount of data. In the case of Outlook, the unchecked buffer would allow a malicious user to create a vCard that contains what Microsoft called "specially malformed data." When a recipient opened such a vCard, the data overflow the available buffer size and crash the e-mail software.
"In a more serious case, a malicious user could exploit the unchecked buffer to run unauthorized code on the other user's computer," Microsoft warned.
Sara Radicati, president and chief executive of The Radicati Group in Palo Alto, California, says she hasn't heard of this hole being a problem yet.
"This is such a low-level issue . . . it just might not have bubbled up yet," she says.

For more enterprise computing news, visit Computerworld. Story copyright © 2011 Computerworld Inc. All rights reserved.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
Speed Up Everything!
PCWorld shows you the secrets to improve performance on all your hardware.
-
Master Windows 7!
Our expert guide will help you get the most out of Windows 7.
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Catch Attach for Microsoft Outlook
- Microsoft Outlook Social Connector Folds Facebook and LinkedIn Into Outlook
- Free SugarSync for Outlook Handles Large File Attachments Neatly
- Gmail Keeper
- Help Solve the Outlook 'General Failure' E-Mail Error
- Free Outlook Add-In PocketKnife Peek Reveals Hidden Info
- eM Client: Affordable Alternative to Microsoft Outlook
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.






















