PT-2001-1908 · Microsoft · Internet Explorer+2

Published

2001-12-06

·

Updated

2020-04-09

·

CVE-2001-0726

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft Exchange 5.5 Server
Description: The issue concerns the improper detection of certain inline scripts by Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server when used with Internet Explorer. This can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.
Recommendations: For Microsoft Exchange 5.5 Server, consider disabling the use of inline scripts in HTML e-mail messages as a temporary workaround until a patch is available. Restrict access to sensitive mailbox operations to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0726

Affected Products

Internet Explorer
Exchange 5.5 Server
Outlook Web Access