CVE-2002-2100Microsoft Outlook vulnerability

3 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
8.1%
top 7.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 30

Description

Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDmicrosoft/outlook2000, 2002+1

🔴Vulnerability Details

2
GHSA
GHSA-5x99-3m4j-vwwh: Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an I2022-04-30
CVEList
CVE-2002-2100: Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an I2005-08-05
CVE-2002-2100 — Microsoft Outlook vulnerability | cvebase