OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: FW: Microsoft Security Bulletin (MS00-034)
From: Weld Pond (weldL0PHT.COM)
Date: Mon May 15 2000 - 12:03:44 CDT


A disappointing part of this security bulletin is where Microsoft
describes the problem: "The vulnerability could allow a malicious web
site operator to take inappropriate action on the computer of a user who
visited his web site."

They neglect to mention the very serious problem of receiving malicious
HTML files via a web enabled mail client such as Outlook. Malicious web
pages are a minor problem. Email viruses and worms are a very serious
problem. They spread exponentially and are harder to track. As long as
IE, Outlook and Windows are so tightly coupled every "malicious web site"
vulnerability is a potential Outlook vulnerability that could be much,
much worse.

-weld