March 10, 2004 1:37 PM PST
Outlook flaw riskier than thought
- Related Stories
-
MSN Messenger flaw allows hard-drive access
March 9, 2004 -
200 days to fix a broken Windows
February 13, 2004 -
Microsoft releases monthly security fixes
October 15, 2003 -
Microsoft upgrades flaw to 'critical'
December 12, 2002
The vulnerability in Outlook 2002, first publicized on Tuesday, when Microsoft
|
| ||||
|
| ||||
|
Get Up to Speed on... Enterprise security Get the latest headlines and company-specific news in our expanded GUTS section. |
||||
|
|
||||
|
|
||||
When Microsoft released its fix, it said it believed that the attack could only be accomplished if a PC user had the "Outlook Today" folder as the default home page in Outlook 2002.
Now, after being alerted by Jouko Pynonnen, the
"After we released the bulletin, we were made aware that (the 'Outlook Today' restriction) could be gotten around by the attacker," said Stephen Toulouse, the program manager for Microsoft's Security Response Center. Toulouse stressed that the patch provided to customers on Tuesday prevents any attack, even though the hole is larger than first thought.
It's the third time in the past 18 months that Microsoft has upgraded the severity of a security flaw. In December 2002,
Pynonnen said Microsoft had not notified him when the patch was planned for release, nor had the company told him how serious it considered the vulnerability.
"I didn't know the issue (was) going to be published this month," he said. Pynonnen added that if he had known, he would have done more research on the mitigating factors Microsoft had assumed.
Pynonnen warned on Wednesday that the vulnerability could be used by an attack to spread a virus through e-mail messages sent to Outlook 2002 users.
Microsoft took more than seven months to patch the vulnerability, a delay that highlights the software giant's focus on quality over speed in its fixes. Some critics have suggested Microsoft
"We always try to figure out how broad the impact (of the flaw) will be and try to cover all the possibilities in the patch," he said.
The fix for the security hole can be downloaded through
See more CNET content tagged:
Microsoft Outlook 2002,
Stephen Toulouse,
severity,
Microsoft Outlook,
security hole
