PT-2001-2242 · Symantec · Norton Antivirus
Publicado
2001-09-07
·
Atualizado
2020-04-02
·
CVE-2001-1099
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Norton AntiVirus for Microsoft Exchange 2000 versions 2.x
Description
The default configuration of the software allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content. This malicious content includes the path in the rejection notice, potentially exposing sensitive information.
Recommendations
For versions 2.x, consider reconfiguring the software to prevent it from including the INBOX file path in rejection notices for emails with malicious attachments. As a temporary workaround, restrict access to the email system to minimize the risk of exploitation.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Norton Antivirus