CVE-2001-0726
Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 16.12% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/exchange server
- Source
- cve@mitre.org
References
- http://www.osvdb.org/5557Broken Link
- http://www.securityfocus.com/bid/3650Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-057Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7663Third Party Advisory, VDB Entry
- http://www.osvdb.org/5557Broken Link
- http://www.securityfocus.com/bid/3650Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-057Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7663Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.