Cross Domain Information Disclosure in Microsoft Outlook Express and Windows Mail
CVE-2007-2227
Currently unrated
Summary
The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail on Windows Vista contains a vulnerability that fails to handle Content-Disposition 'notifications' adequately. This oversight enables remote attackers to exploit the flaw and gain access to sensitive information from different Internet Explorer domains. As a result, users of these applications may unknowingly expose their data to malicious parties.
References
EPSS Score
51% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved