PT-2007-3564 · Microsoft · Windows Vista+3

Published

2007-06-12

·

Updated

2018-10-16

·

CVE-2007-2227

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Outlook Express version 6 Windows Mail in Windows Vista
Description The issue concerns the MHTML protocol handler, which does not properly handle Content-Disposition notifications. This allows remote attackers to obtain sensitive information from other Internet Explorer domains.
Recommendations For Microsoft Outlook Express version 6, update to a version that properly handles Content-Disposition notifications. For Windows Mail in Windows Vista, apply the necessary patch or configuration change to correct the MHTML protocol handler's handling of Content-Disposition notifications.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2227

Affected Products

Internet Explorer
Outlook Express
Windows Mail
Windows Vista