AplusWebMaster
Topic Starter
FYI…
MS Multiple E-Mail Client Address Spoofing Vulnerability
- http://www.idefense.com/application/poi/di…vulnerabilities
iDEFENSE Security Advisory 04.08.05
"….Vulnerability specifically exists in message header parsing and allows an attacker to spoof the "From" field that is displayed on the user's screen. Within the SMTP header, when the From field contains multiple comma-separated addresses, Outlook and OWA will only display the first address…
IV. DETECTION
Microsoft Outlook as distributed with Office XP and 2003 as well as Outlook Web Access as distributed with Exchange 2003 have been confirmed as vulnerable. Prior versions are suspected to be affected as well.
Microsoft Outlook Express is not affected by this issue.
V. WORKAROUND
Examine the full mail headers of any suspicious e-mail messages prior to taking described actions or following live links.
VI. VENDOR RESPONSE
Microsoft has reviewed the issue and has made the determination that while a bug fix may be implemented in a future service pack, a security advisory/patch will not be released for this issue…"
- http://isc.sans.org/diary.php?date=2005-04-09
Updated April 9th 2005 23:22 UTC
"…If an email is constructed so that the "From:" header contains multiple senders, the Outlook clients will only display the first sender. Unfortunately, this provides yet another way that Phishers can spoof the apparent sender of fraudulent scam emails and make them seem more legitimate. [Of course, legitimate organizations don't send emails that encourage you to click links to enter personal data or to apply software updates to your system in the first place!]…"

MS Multiple E-Mail Client Address Spoofing Vulnerability
- http://www.idefense.com/application/poi/di…vulnerabilities
iDEFENSE Security Advisory 04.08.05
"….Vulnerability specifically exists in message header parsing and allows an attacker to spoof the "From" field that is displayed on the user's screen. Within the SMTP header, when the From field contains multiple comma-separated addresses, Outlook and OWA will only display the first address…
IV. DETECTION
Microsoft Outlook as distributed with Office XP and 2003 as well as Outlook Web Access as distributed with Exchange 2003 have been confirmed as vulnerable. Prior versions are suspected to be affected as well.
Microsoft Outlook Express is not affected by this issue.
V. WORKAROUND
Examine the full mail headers of any suspicious e-mail messages prior to taking described actions or following live links.
VI. VENDOR RESPONSE
Microsoft has reviewed the issue and has made the determination that while a bug fix may be implemented in a future service pack, a security advisory/patch will not be released for this issue…"
- http://isc.sans.org/diary.php?date=2005-04-09
Updated April 9th 2005 23:22 UTC
"…If an email is constructed so that the "From:" header contains multiple senders, the Outlook clients will only display the first sender. Unfortunately, this provides yet another way that Phishers can spoof the apparent sender of fraudulent scam emails and make them seem more legitimate. [Of course, legitimate organizations don't send emails that encourage you to click links to enter personal data or to apply software updates to your system in the first place!]…"