March 10, 2004 1:37 PM PST

Outlook flaw riskier than thought

Microsoft has raised the severity rating of an Outlook flaw to "critical," the highest level, after its initial analysis was challenged by the researcher who found the security hole.

The vulnerability in Outlook 2002, first publicized on Tuesday, when Microsoft released a patch, could allow an attacker to use a malicious Web site to cause an affected PC to download and execute a program.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


When Microsoft released its fix, it said it believed that the attack could only be accomplished if a PC user had the "Outlook Today" folder as the default home page in Outlook 2002. Now, after being alerted by Jouko Pynonnen, the Finnish security researcher who found the flaw, it says the potential for attack is greater.

"After we released the bulletin, we were made aware that (the 'Outlook Today' restriction) could be gotten around by the attacker," said Stephen Toulouse, the program manager for Microsoft's Security Response Center. Toulouse stressed that the patch provided to customers on Tuesday prevents any attack, even though the hole is larger than first thought.

It's the third time in the past 18 months that Microsoft has upgraded the severity of a security flaw. In December 2002, it upped two "moderate" vulnerabilities to "critical" status, after the researchers who found the holes cast doubt on Microsoft's initial classification.

Pynonnen said Microsoft had not notified him when the patch was planned for release, nor had the company told him how serious it considered the vulnerability.

"I didn't know the issue (was) going to be published this month," he said. Pynonnen added that if he had known, he would have done more research on the mitigating factors Microsoft had assumed.

Pynonnen warned on Wednesday that the vulnerability could be used by an attack to spread a virus through e-mail messages sent to Outlook 2002 users.

Microsoft took more than seven months to patch the vulnerability, a delay that highlights the software giant's focus on quality over speed in its fixes. Some critics have suggested Microsoft should produce patches faster, but Microsoft's Toulouse said finding the full extent of flaws and eliminating patch problems are company focal points.

"We always try to figure out how broad the impact (of the flaw) will be and try to cover all the possibilities in the patch," he said.

The fix for the security hole can be downloaded through Microsoft's Download Center or by applying Service Pack 3 for Office XP, which was released on Tuesday.

See more CNET content tagged:
Microsoft Outlook 2002, Stephen Toulouse, severity, Microsoft Outlook, security hole

Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Dell planning to ditch factories

    Dell's new CFO Brian Gladden has said that the company "more work to be done," to improve profitability and decrease costs. The Wall Street Journal is reporting that the company is planning to lower costs by selling off its factories.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • Digital Noise: Music and Tech

    Was 1980s music that bad?

    NPR asks listeners which year featured the best music, and the 1980s emerge as a bleak era. Personally, the '80s figure prominently in my collection, but well behind the 1970s.

  • Beyond Binary

    Microsoft begins big ad push

    Microsoft's multi-year push, estimated at $300 million, begins with a spot featuring Bill Gates and Jerry Seinfeld aired during Thursday's NFL game.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Digital Media

    Michael Moore plans Net-only film premiere

    Filmmaker plans to premiere his latest documentary exclusively on the Internet for free, forgoing the traditional theatrical release.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Politics and Law

    What you can--and can't--find about Palin on the Internet

    John McCain's choice of Sarah Palin as a running mate has inspired a wealth of creativity on the Internet.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • Crossfade

    Ying Yang Twins, 'Look Back At It': Free MP3 of the Day

    This amped-up duo gets the party started with a mix of crisp, Southern hip-hop beats and shout-along rhymes. Download a free MP3 of "Look Back At It" courtesy of CNET Download Music.

  • Green Tech

    Clean-tech group forms to support Obama

    "Clean Tech and Green Business for Obama" aims to raise $1 million for the Democratic presidential nominee while elevating issues of climate change and alternative energy.