PGP Corporation PGP Embedded OLE...

- AV AC AU C I A
发布: 2003-03-12
修订: 2025-04-13

A weakness has been reported for the PGP application that may allow an attacker to embed malicious OLE objects into email messages. This issue occurs because PGP will first strip any OLE objects that are inserted into email messages and then verify the message signature. This poses an issue for the end user as they are not notified by PGP of any stripped OLE objects. A malicious attacker may be able to insert a malicious OLE object into a body of a hijacked email message and then send the email to a victim user where the malicious object may be executed.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息