PT-2004-1638 · Microsoft · Outlook+1
Publicado
2004-06-08
·
Atualizado
2021-07-23
·
CVE-2004-0526
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Explorer (affected versions not specified)
Outlook (affected versions not specified)
Description
The issue allows remote attackers to spoof a legitimate URL in the status bar, facilitating a phishing attack. This is achieved by using A HREF tags with modified
alt values that point to the legitimate site, combined with an image map whose href points to the malicious site.Recommendations
For Internet Explorer, consider disabling the use of image maps in conjunction with modified
alt values until a fix is available.
For Outlook, restrict the display of external images to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Internet Explorer
Outlook