Oval Definition:
oval:org.mitre.oval:def:1055
Revision Date
:
2007-02-20
Version
:
43
Title
:
Windows Address Book Contact Record Vulnerability
Description
:
Unspecified vulnerability in Microsoft Outlook Express 6 and earlier allows remote attackers to execute arbitrary code via a crafted contact record in a Windows Address Book (WAB) file.
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2006-2386
Platform(s)
:
Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows XP
Product(s)
:
Microsoft Outlook Express
Definition Synopsis
Win2K,SP4
Microsoft Windows 2000 SP4 or later is installed
AND
Microsoft Outlook Express 5.5 SP2 is installed.
AND
the version of inetcomm.dll is less than 5.50.4971.600
OR
WinXP,SP2
Microsoft Windows 2000 SP4 or later is installed
AND
Microsoft Outlook Express 6 SP1 is installed.
AND
the version of inetcomm.dll is less than 6.0.2800.1896
OR
WinXP,SP2
Microsoft Windows XP SP2 or later is installed
AND
Microsoft Outlook Express 6.0 for Windows XP/2003 is installed
AND
the version of inetcomm.dll is less than 6.0.2900.3028
OR
WinXP,SP1 (64-bit)
Microsoft Windows XP SP1 (64-bit) is installed
AND
Microsoft Outlook Express 6.0 for Windows XP/2003 is installed
AND
the version of inetcomm.dll is less than 6.0.3790.2826
OR
S03-Gold
Microsoft Windows Server 2003 (x86) Gold is installed
AND
Microsoft Outlook Express 6.0 for Windows XP/2003 is installed
AND
the version of inetcomm.dll is less than 6.0.3790.607
OR
S03,SP1
Microsoft Windows Server 2003 SP1 (x86) is installed
AND
Microsoft Outlook Express 6.0 for Windows XP/2003 is installed
AND
the version of inetcomm.dll is less than 6.0.3790.2826
BACK