Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
| Software | From | Fixed in |
|---|---|---|
| microsoft / frontpage | 2003 | 2003.x |
| microsoft / sharepoint_designer | 2007 | 2007.x |
| microsoft / office_communicator | 2007 | 2007.x |
| microsoft / access | 2007 | 2007.x |
| microsoft / visio_professional | 2007 | 2007.x |
| microsoft / outlook | 2003 | 2003.x |
| microsoft / project_standard | 2007 | 2007.x |
| microsoft / powerpoint | 2003 | 2003.x |
| microsoft / infopath | 2007 | 2007.x |
| microsoft / infopath | 2003 | 2003.x |
| microsoft / visio_standard | 2007 | 2007.x |
| microsoft / windows_live_mail | 2008 | 2008.x |
| microsoft / publisher | 2003 | 2003.x |
| microsoft / onenote | 2003 | 2003.x |
| microsoft / outlook | 2007 | 2007.x |
| microsoft / powerpoint | 2007 | 2007.x |
| microsoft / excel | 2007 | 2007.x |
| microsoft / publisher | 2007 | 2007.x |
| microsoft / excel | 2003 | 2003.x |
| microsoft / project_professional | 2007 | 2007.x |
| microsoft / office | 2007-sp1 | 2007-sp1.x |
| microsoft / office | 2007 | 2007.x |
| microsoft / groove | 2007 | 2007.x |