New Outlook Bug Doesn't Require Users To Interact With Emails To Be Compromised (softpedia.com)
An anonymous reader writes: A new bug in Outlook allows attackers only to send you an email, and without clicking or downloading attachments, a user's computer can be compromised. The bug [PDF] is because Outlook allows Flash objects to be previewed without a sandbox. Flash files are demon spawns and attackers can put exploits in malicious files, which when previewed or viewed inside an Outlook application will automatically execute their payload.
The Melissa mail worm seems to be forgotten, but there's a new generation of coders now that weren't even in school when that occurred.
If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
Years ago we were warned to turn off Outlook previews, for exactly this reason. Also, my copy of Outlook doesn't download or render attachments (or even images) unless told to, for every individual email. As far as I know, that is the default behaviour. The danger is that you can whitelist senders so that their attachments are downloaded without confirmation, and spammers often use commonly used email addresses as the originator.
The summary is incorrect as well. FTA: "The only condition is that the user views or previews the email in which the attacker has embedded a malicious Flash file." So you still need to click. The only exception is if your Outlook is set to always download attachments, show a preview, and if the malicious email is the last one to arrive, since the mail will then be shown in the preview window upon opening Outlook.
Lastly, Flash needs to die
If construction was anything like programming, an incorrectly fitted lock would bring down the entire building...
Why doesn't the summary mention that this was fixed by an update released on patch tuesday dec 8?
Lastly, Flash needs to die
Just curious... why are people on a coding site declaring "Flash needs to die" instead of something like, Flash needs to be completely deconstructed and rewritten by the open source community using the most conservative style of programming, a system that forces a multi-person review of commits, hit with the best enumeration tools we have, so that arbitrary code execution is not possible? Which might be possible because processor speed has improved since it was first designed and the assembly level hacks that made it possible areno longer necessary? And when we are done, the worst thing that could ever happen is that someone might display goatse.cx inside a Flash window?
Instead of busting into the kitchen, grabbing pans off the wall and showing the chef how steak should be done, we sit at the table banging our forks and knives, shouting, "Down with meat!"
It's easy to make fun of Outlook, where with maliciously crafted embedded binary OLE blobs you can trigger exploits in many versions of Microsoft products. The faults lie in the products themselves not the Blob. But Flash self contained and lives inside a little rectangle. It is cross platform, amply documented and widely used today. Why must it die? So that generations of beloved Internet content can be 'destroyed' overnight? It almost smells like book-burning.
<blink>down the rabbit hole</blink>
I really don't understand why TFS starts with "A new bug in Outlook..." - after all, it's the SAME bug in Outlook -- since about 1997. Looks like the marketing department at Microsoft, in their endless desire for yet more whizzo shit has (potentially/inevitably) won yet another Pwnie Award. Whenever I see someone with a palm-shaped bruise on their forehead, I know they're a Windows sysadmin. This one reminds me of that Windows Explorer bug that executed arbitrary code from inside image (picture) files when you opened the directory they were stored in.
"As if millions of voices cried out 'DUH!!!' and were suddenly silenced."
Well, the fortune cookie did say "Outlook not so good".
Don't waste your vote! Vote for whoever you want, unless you live in a swing state it won't matter anyways