Skip to content

Outlook 2010: actual characters exposed in password fields of secue dialogs #4095

@nvaccessAuto

Description

@nvaccessAuto

Reported by mdcurran on 2014-04-28 03:04
In password fields in Outlook 2010 when ITextDocument is not available, actual characters are exposed which is obviously a security risk. Standard edit controls have already been protected against, but richEdit controls (no ITextDocument) have not. _getTextRange on the Edit TextInfo.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions