CVE-2004-2137
Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 26.14% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/outlook express
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/12376Patch, Vendor Advisory
- http://securitytracker.com/id?1011067Patch
- http://support.microsoft.com/kb/843555Patch, Vendor Advisory
- http://www.networksecurity.fi/advisories/outlook-bcc.htmlPatch, Vendor Advisory
- http://www.osvdb.org/9167
- http://www.securityfocus.com/bid/11040
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17098
- http://secunia.com/advisories/12376Patch, Vendor Advisory
- http://securitytracker.com/id?1011067Patch
- http://support.microsoft.com/kb/843555Patch, Vendor Advisory
- http://www.networksecurity.fi/advisories/outlook-bcc.htmlPatch, Vendor Advisory
- http://www.osvdb.org/9167
- http://www.securityfocus.com/bid/11040
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17098
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.