CVE-2007-2227
The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 25.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information Disclosure Vulnerability."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 25.04% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/outlook express · microsoft/windows mail
- Source
- secure@microsoft.com
References
- http://archive.openmya.devnull.jp/2007.06/msg00060.html
- http://openmya.hacker.jp/hasegawa/security/ms07-034.txt
- http://osvdb.org/35346
- http://secunia.com/advisories/25639
- http://www.securityfocus.com/archive/1/471947/100/0/threaded
- http://www.securityfocus.com/archive/1/472002/100/0/threaded
- http://www.securityfocus.com/bid/24410
- http://www.securitytracker.com/id?1018233
- http://www.securitytracker.com/id?1018234
- http://www.us-cert.gov/cas/techalerts/TA07-163A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/2154
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-034
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2085
- http://archive.openmya.devnull.jp/2007.06/msg00060.html
- http://openmya.hacker.jp/hasegawa/security/ms07-034.txt
- http://osvdb.org/35346
- http://secunia.com/advisories/25639
- http://www.securityfocus.com/archive/1/471947/100/0/threaded
- http://www.securityfocus.com/archive/1/472002/100/0/threaded
- http://www.securityfocus.com/bid/24410
- http://www.securitytracker.com/id?1018233
- http://www.securitytracker.com/id?1018234
- http://www.us-cert.gov/cas/techalerts/TA07-163A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/2154
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-034
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2085
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.