PT-2001-2242 · Symantec · Norton Antivirus

Published

2001-09-07

·

Updated

2020-04-02

·

CVE-2001-1099

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Norton AntiVirus for Microsoft Exchange 2000 versions 2.x
Description The default configuration of the software allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content. This malicious content includes the path in the rejection notice, potentially exposing sensitive information.
Recommendations For versions 2.x, consider reconfiguring the software to prevent it from including the INBOX file path in rejection notices for emails with malicious attachments. As a temporary workaround, restrict access to the email system to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2001-1099

Affected Products

Norton Antivirus