PT-2001-2231 · Microsoft · Outlook+1
Published
2001-06-05
·
Updated
2017-10-10
·
CVE-2001-1088
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook versions 8.5 and earlier
Microsoft Outlook Express versions 5 and earlier
Description
The issue concerns a scenario where an untrusted remote attacker could potentially spoof legitimate addresses and intercept email. This is possible because the software does not notify the user when the
Reply-To address differs from the From address, given that the "Automatically put people I reply to in my address book" option is enabled.Recommendations
For Microsoft Outlook versions 8.5 and earlier, disable the "Automatically put people I reply to in my address book" option to prevent address book modifications by potentially spoofed emails.
For Microsoft Outlook Express versions 5 and earlier, disable the "Automatically put people I reply to in my address book" option to minimize the risk of intercepting emails intended for other users.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Outlook
Outlook Express