Information Disclosure in Outlook Express 6.0 by Microsoft
CVE-2004-2137
Currently unrated
Summary
A vulnerability in Microsoft Outlook Express 6.0 allows the disclosure of blind carbon copy (BCC) recipients when sending multipart email messages. With the 'Break apart messages larger than' setting enabled, recipients listed in the To and CC fields may see the BCC recipients, potentially exposing sensitive information to unauthorized users. This flaw poses a risk when confidential communication is handled via email, as it undermines privacy and could result in data leakage.
References
EPSS Score
39% chance of being exploited in the next 30 days.
Timeline
Vulnerability Reserved
Vulnerability published