PT-2001-2231 · Microsoft · Outlook+1

Publicado

2001-06-05

·

Atualizado

2017-10-10

·

CVE-2001-1088

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Outlook versions 8.5 and earlier Microsoft Outlook Express versions 5 and earlier
Description The issue concerns a scenario where an untrusted remote attacker could potentially spoof legitimate addresses and intercept email. This is possible because the software does not notify the user when the Reply-To address differs from the From address, given that the "Automatically put people I reply to in my address book" option is enabled.
Recommendations For Microsoft Outlook versions 8.5 and earlier, disable the "Automatically put people I reply to in my address book" option to prevent address book modifications by potentially spoofed emails. For Microsoft Outlook Express versions 5 and earlier, disable the "Automatically put people I reply to in my address book" option to minimize the risk of intercepting emails intended for other users.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1088

Produtos afetados

Outlook
Outlook Express