Information Disclosure in Outlook Express 6.0 by Microsoft
CVE-2004-2137

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
31 December 2004

Summary

A vulnerability in Microsoft Outlook Express 6.0 allows the disclosure of blind carbon copy (BCC) recipients when sending multipart email messages. With the 'Break apart messages larger than' setting enabled, recipients listed in the To and CC fields may see the BCC recipients, potentially exposing sensitive information to unauthorized users. This flaw poses a risk when confidential communication is handled via email, as it undermines privacy and could result in data leakage.

References

EPSS Score

39% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.