PT-2001-2231 · Microsoft · Outlook+1

Published

2001-06-05

·

Updated

2017-10-10

·

CVE-2001-1088

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Outlook versions 8.5 and earlier Microsoft Outlook Express versions 5 and earlier
Description The issue concerns a scenario where an untrusted remote attacker could potentially spoof legitimate addresses and intercept email. This is possible because the software does not notify the user when the Reply-To address differs from the From address, given that the "Automatically put people I reply to in my address book" option is enabled.
Recommendations For Microsoft Outlook versions 8.5 and earlier, disable the "Automatically put people I reply to in my address book" option to prevent address book modifications by potentially spoofed emails. For Microsoft Outlook Express versions 5 and earlier, disable the "Automatically put people I reply to in my address book" option to minimize the risk of intercepting emails intended for other users.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1088

Affected Products

Outlook
Outlook Express