Desktop Central helps administrators to automate patch deployment of both Microsoft and Non-Microsoft Applications from a central point.
|
|
| MS03-014 Bulletin Details |
Microsoft Security Bulletins |
| Bulletin ID: | MS03-014 |
| Title | Cumulative Patch for Outlook Express (330994) |
| Summary: | MHTML stands for MIME Encapsulation of Aggregate HTML. MHTML is an Internet standard that defines the MIME (Multipurpose Internet Mail Extensions) structure used to send HTML content in e-mail message bodies. The MHTML URL Handler in Windows is part of Outlook Express and provides a URL type that can be used on the local machine. This URL type (MHTML://) allows MHTML documents to be launched from a command line, from Start/Run, using Windows Explorer or from within Internet Explorer.
A vulnerability exists in the MHTML URL Handler that allows any file that can be rendered as text to be opened and rendered as part of a page in Internet Explorer. As a result, it would be possible to construct a URL that referred to a text file that was stored on the local computer and have that file render as HTML. If the text file contained script, that script would execute when the file was accessed. Since the file would reside on the local computer, it would be rendered in the Local Computer Security Zone. Files that are opened within the Local Computer Zone are subject to fewer restrictions than files opened in other security zones. |
| Knowledgebase: |
330994 |
List of Patches
|
| |
|
|
|
| |
|
|
| Patch Mgmt Features |
 |
|
|
| Desktop Mgmt Features |
 |
|
|
| Forums |
 |
|
|
| |
|