PT-2001-2150 · Microsoft · Outlook Express
Publicado
2001-09-12
·
Atualizado
2017-12-19
·
CVE-2001-0999
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Outlook Express version 6.00
Description
The issue allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain. This behavior is contrary to the expected behavior that text/plain messages will not run script.
Recommendations
For Outlook Express version 6.00, consider disabling the execution of scripts in text/plain messages as a temporary workaround until a patch is available. Restrict access to potentially malicious emails to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Outlook Express