Original release date: July 26, 2000<BR>
Source: CERT/CC<BR>

<P>A complete revision history is at the end of this file.

<A NAME="affected">
<H3>Systems Affected</H3>

<UL>
<LI>Any system running Microsoft Outlook Express 4.0 or 4.01</LI>
<LI>Any system running Microsoft Outlook Express 5.0 or 5.01</LI>
<LI>Any system running Microsoft Outlook 98</LI>
<LI>Any system running Microsoft Outlook 2000</LI>
</UL>

<A NAME="overview">
<H2>Overview</H2>

<P>Microsoft has recently released Microsoft Security Bulletin
MS00-046, in which they announced a patch for the "Cache Bypass"
vulnerability.  By exploiting this vulnerability, an attacker can use
an HTML-formatted message to read certain types of files on the
victim's machine.

<P>In addition, because this vulnerability also allows the attacker to
store files on the victim's machine, it can be used in conjunction
with existing vulnerabilities to execute arbitrary code on the target
system.

<A NAME="description">
<H2>I. Description</H2>

<H3>"Cache Bypass" Vulnerability</H3>

<P>Typically, all files downloaded by either Outlook or Internet
Explorer are stored in an area known as a cache.  The cache serves two
main purposes.  First, it provides temporary storage for online
content, which minimizes the amount of data that must be transferred
when refreshing a page.  Second, it provides an area where Internet
content can be downloaded to the local machine and accessed with the
same security policy as remote content.

<P>This vulnerability allows attackers to use an HTML-formatted
message to store files outside the cache.  Inside the cache, the files
are governed by the security policy of the "Internet Zone," but
outside they are governed by the "Local Computer Zone."  Once a file
is stored in the "Local Computer Zone," the security policy of the
"Internet Zone" no longer applies to it.  This could put systems at
risk because the security policies of the "Local Computer Zone" are
typically more permissive than those of the "Internet Zone."

<A NAME="impact">
<H2>II. Impact</H2>

<P>When exploited, this vulnerability allows an attacker to store an
HTML file in an area that is not protected by the policies of the
"Internet Zone."  This file may then be used to open arbitrary files
on the victim's machine and send their contents back to the attacker.

<P>In addition, the "Cache Bypass" vulnerability could be used in
conjunction with other vulnerabilities to allow an intruder to execute
arbitrary code on the victim's machine.

<A NAME="solution">
<H2>III. Solution</H2>

<P>Microsoft has released Microsoft Security Bulletin MS00-046, which
points to a patch for this vulnerability.  We strongly encourage you
to read this bulletin and apply the patch.  MS00-046 is available at<P>

<DL><DD>
  <A HREF="http://www.microsoft.com/technet/security/bulletin/MS00-046.asp">
  http://www.microsoft.com/technet/security/bulletin/MS00-046.asp</A>
</DL>

<HR NOSHADE>

<P>The CERT Coordination Center would like to thank Microsoft for its assistance in developing this advisory.

<HR NOSHADE>

<P>Author: <a href="mailto:cert@cert.org?subject=CA-2000-14%20Feedback">Jeffrey P. Lanza</a>

<P></P>

<!--#include virtual="/include/footer_nocopyright.html" -->

<P>Copyright 2000 Carnegie Mellon University</P>

<P>Revision History
<PRE>
July 26, 2000:  Initial release
</PRE>