Critical Flaw in Email Programs Exposes Millions to Catastrophic Attacks
Computer security experts have identified a severe flaw in two widely used email programs, Microsoft's Outlook Express and Outlook 98, and Netscape's Communicator, which could allow hackers to execute malicious commands and potentially erase computers' hard drives. Despite the absence of reported attacks, experts fear that the hacker community is aware of the flaw, and the situation is becoming increasingly alarming. Researchers have confirmed that the vulnerability exists across various Windows machines, including Windows 3.1 to NT, as well as on Solaris operating systems and Apple computers.
Key Takeaways:
- The flaw allows hackers to send a booby-trapped message that can execute malicious commands, including erasing a computer's hard drive, without the user ever opening the message.
- The vulnerability is present in Microsoft's Outlook Express and Outlook 98, and Netscape's Communicator, and may also affect other email programs like Eudora.
- Firewalls and anti-viral software are ineffective in preventing the attack, making it a significant concern for users.
- The flaw exists on any flavor of Windows machine, from 3.1 to NT, as well as on Solaris operating systems and Apple computers.
- Both Netscape and Microsoft have acknowledged the problem and are working on software patches, with Microsoft's patch available at http://www.microsoft.com/ie/security and Netscape's patch expected soon at http://www.netscape.com.
- The flaw has been compared in significance to the defect that allowed Robert T. Morris to bring down the entire Internet 10 years ago using an electronic "worm."
- Experts fear that the flaw could lead to a new Internet-based worm that could be much worse than Morris's version.
Statistics:
- The flaw is among the most serious security holes ever identified.
- The vulnerability is present in three widely used email programs: Microsoft's Outlook Express, Outlook 98, and Netscape's Communicator.
- The attacker does not need to open the message to trigger the attack, and it can be triggered by simply trying to delete the email.
- The vulnerability affects any flavor of Windows machine, from 3.1 to NT, as well as on Solaris operating systems and Apple computers.
- Microsoft's patch is available at http://www.microsoft.com/ie/security, and Netscape's patch is expected soon at http://www.netscape.com.
Sources:
- San Jose Mercury News, (c) 1998.
- Microsoft Corp.
- Netscape Communication's Corp.
- Ari Takanen and Marko Laakso of Finland's Oulu University Secure Programming Group.
- Eugene H. Spafford, director of the new Center for Education and Research in Information Assurance and Security at Purdue University.
- Russ Cooper, who moderates the respected computer security mailing list called NTBugtraq from his home in Lindsey, Ontario.
- George Meng, a group product manager for Microsoft.