PT-2001-2150 · Microsoft · Outlook Express

Published

2001-09-12

·

Updated

2017-12-19

·

CVE-2001-0999

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Outlook Express version 6.00
Description The issue allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain. This behavior is contrary to the expected behavior that text/plain messages will not run script.
Recommendations For Outlook Express version 6.00, consider disabling the execution of scripts in text/plain messages as a temporary workaround until a patch is available. Restrict access to potentially malicious emails to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0999

Affected Products

Outlook Express