CVE Vulnerabilities

CVE-2001-1088

Published: Jun 05, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the Automatically put people I reply to in my address book option enabled, do not notify the user when the Reply-To address is different than the From address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.

Affected Software

NameVendorStart VersionEnd Version
OutlookMicrosoft97 (including)97 (including)
OutlookMicrosoft98 (including)98 (including)
OutlookMicrosoft2000 (including)2000 (including)
Outlook_expressMicrosoft4.0 (including)4.0 (including)
Outlook_expressMicrosoft4.5 (including)4.5 (including)
Outlook_expressMicrosoft4.27.3110 (including)4.27.3110 (including)
Outlook_expressMicrosoft4.72.2106 (including)4.72.2106 (including)
Outlook_expressMicrosoft4.72.3120.0 (including)4.72.3120.0 (including)
Outlook_expressMicrosoft4.72.3612 (including)4.72.3612 (including)
Outlook_expressMicrosoft5.0 (including)5.0 (including)
Outlook_expressMicrosoft5.5 (including)5.5 (including)

References