PT-2001-2242 · Symantec · Norton Antivirus
Published
2001-09-07
·
Updated
2020-04-02
·
CVE-2001-1099
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Norton AntiVirus for Microsoft Exchange 2000 versions 2.x
Description
The default configuration of the software allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content. This malicious content includes the path in the rejection notice, potentially exposing sensitive information.
Recommendations
For versions 2.x, consider reconfiguring the software to prevent it from including the INBOX file path in rejection notices for emails with malicious attachments. As a temporary workaround, restrict access to the email system to minimize the risk of exploitation.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Norton Antivirus