Critical Flaw in Email Programs Exposes Millions to Catastrophic Attacks

Computer security experts have identified a severe flaw in two widely used email programs, Microsoft's Outlook Express and Outlook 98, and Netscape's Communicator, which could allow hackers to execute malicious commands and potentially erase users' hard drives. This flaw is considered one of the most significant security vulnerabilities ever discovered, and experts fear that it could be exploited by the hacker community. The flaw can be triggered without even opening the email, and current security methods, including firewalls and anti-viral software, are unable to prevent it.

Key Takeaways:

  • The flaw allows hackers to send booby-trapped emails that can execute malicious commands, such as erasing a computer's hard drive.
  • The vulnerability exists in Outlook Express and Outlook 98, as well as in Netscape's Communicator, and may also affect other email programs, such as Eudora.
  • The flaw can be triggered without opening the email, and even trying to delete the email can activate the attack.
  • Firewalls and anti-viral software are unable to prevent this type of attack.
  • Microsoft has released a software patch for the flaw, available at http://www.microsoft.com/ie/security, and Netscape's patch is expected to be released soon at http://www.netscape.com.
  • Experts fear that most users will not install the patches, and the "black hat" part of the hacker community may start exploiting the vulnerability within days.

Statistics:

  • The flaw has been identified in three widely used email programs: Microsoft's Outlook Express and Outlook 98, and Netscape's Communicator.
  • The vulnerability exists on Windows machines from 3.1 to NT, as well as on computers running Sun Microsystems' Solaris operating system and Apple Computer's operating system.
  • There have been no reports of the flaw being exploited outside of a laboratory setting.
  • Until the patches are installed, users are at risk of falling victim to potential catastrophic attacks.

Sources:

  • Microsoft Corp.
  • Netscape Communication's Corp.
  • Finnish researchers at Oulu University Secure Programming Group, including Ari Takanen and Marko Laakso.
  • Eugene H. Spafford, director of the Center for Education and Research in Information Assurance and Security at Purdue University.
  • George Meng, group product manager for Microsoft.