Cross Domain Information Disclosure in Microsoft Outlook Express and Windows Mail
CVE-2007-2227

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
12 June 2007

Summary

The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail on Windows Vista contains a vulnerability that fails to handle Content-Disposition 'notifications' adequately. This oversight enables remote attackers to exploit the flaw and gain access to sensitive information from different Internet Explorer domains. As a result, users of these applications may unknowingly expose their data to malicious parties.

References

EPSS Score

51% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.