PT-2003-1306 · Microsoft · Exchange Server+1

Published

2003-02-07

·

Updated

2018-10-12

·

CVE-2003-0007

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Outlook version 2002
Description The issue arises from how Microsoft Outlook 2002 handles requests to encrypt email messages with V1 Exchange Server Security certificates. This improper handling causes Outlook to send the email in plaintext, potentially leading to information disclosure.
Recommendations For Microsoft Outlook 2002, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0007

Affected Products

Exchange Server
Outlook