PT-2004-1638 · Microsoft · Outlook+1
Published
2004-06-08
·
Updated
2021-07-23
·
CVE-2004-0526
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Explorer (affected versions not specified)
Outlook (affected versions not specified)
Description
The issue allows remote attackers to spoof a legitimate URL in the status bar, facilitating a phishing attack. This is achieved by using A HREF tags with modified
alt values that point to the legitimate site, combined with an image map whose href points to the malicious site.Recommendations
For Internet Explorer, consider disabling the use of image maps in conjunction with modified
alt values until a fix is available.
For Outlook, restrict the display of external images to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer
Outlook