Hello all
Forgive me if this has already been posted and forgive the annoying asterisks to make this post stand out but I thought I’d do my best to make everyone aware of this in case you’re affected.
Information is here…
http://www.idefense.com/application/poi/display?id=111&type=vulnerabilities
Simply put…
A URL can launch the Notes client using the = paramater to specify a path to a malicious data directory.
An attacker can set up a unc share on the net with a dodgy data direcory and cause you to launch Notes using that directory.
The vulnerability says that dll’s, etc can be launched but I’m not sure about this as the notes.ini points to the data directory, not the program directory.
Sounds like a biggie to me if you can see unc shares through your firewall. Any thoughts?