Vulnerabilities > CVE-2001-1088 - Unspecified vulnerability in Microsoft Outlook and Outlook Express

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
microsoft
exploit available

Summary

Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.

Exploit-Db

descriptionMicrosoft Outlook 97/98/2000/4/5 Address Book Spoofing Vulnerability. CVE-2001-1088. Remote exploit for windows platform
idEDB-ID:20899
last seen2016-02-02
modified2001-06-05
published2001-06-05
reporter3APA3A
sourcehttps://www.exploit-db.com/download/20899/
titleMicrosoft Outlook 97/98/2000/4/5 Address Book Spoofing Vulnerability