Microsoft Crypto API 5.131.2600.2180 up to and including 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote malicious users to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
microsoft groove 2007 |
||
microsoft infopath 2003 |
||
microsoft outlook 2007 |
||
microsoft powerpoint 2003 |
||
microsoft visio professional 2007 |
||
microsoft visio standard 2007 |
||
microsoft access 2007 |
||
microsoft office 2007 |
||
microsoft office communicator 2007 |
||
microsoft project standard 2007 |
||
microsoft publisher 2003 |
||
microsoft excel 2003 |
||
microsoft excel 2007 |
||
microsoft frontpage 2003 |
||
microsoft onenote 2003 |
||
microsoft outlook 2003 |
||
microsoft publisher 2007 |
||
microsoft sharepoint designer 2007 |
||
microsoft infopath 2007 |
||
microsoft powerpoint 2007 |
||
microsoft project professional 2007 |
||
microsoft windows live mail 2008 |