Cross Domain Information Disclosure in Microsoft Outlook Express and Windows Mail
CVE-2007-2227
Currently unrated
What is CVE-2007-2227?
The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail on Windows Vista contains a vulnerability that fails to handle Content-Disposition 'notifications' adequately. This oversight enables remote attackers to exploit the flaw and gain access to sensitive information from different Internet Explorer domains. As a result, users of these applications may unknowingly expose their data to malicious parties.