Saturday, March 24, 2007

Vista’s Windows Mail vulnerable to attack

A just-disclosed bug in Windows Vista's built-in e-mail program can be used by hackers to run malicious code on a victimized PC, said a researcher today who two weeks ago touted an exploit-for-sale service.

Microsoft acknowledged the report, and said it is investigating the vulnerability.

A hacker known as "Kingcope" published proof-of-concept code to show that remote code execution is possible if a user is tricked into clicking a malicious link.

The error is that Windows Mail will execute any executable file if a folder exists with the same name.

Read the article HERE.

0 Comments:

Post a Comment

<< Home