PT-2004-3033 · Microsoft · Outlook Express

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2137

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Outlook Express version 6.0
Description The issue allows remote attackers to obtain sensitive information by leaking the BCC recipients of a message to the addresses listed in the To and CC fields when sending multipart e-mail messages using the "Break apart messages larger than" setting.
Recommendations For Outlook Express version 6.0, avoid using the "Break apart messages larger than" setting when sending emails with BCC recipients to prevent information leakage.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2137

Affected Products

Outlook Express