CVE-2001-0340
7.5
CVSS Score
High
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Link copied!
Description
An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
P
Availability
P
Affected Software Configurations
- a microsoft exchange_server 5.5 - * * * * * *
- a microsoft exchange_server 2000 - * * * * * *
Weaknesses (CWE)
- CWE-434
References & External Links
- http://www.ciac.org/ciac/bulletins/l-091.shtml
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-030
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6652
- http://www.ciac.org/ciac/bulletins/l-091.shtml
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-030
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6652
External Resources
CVE History Timeline
Jan 01, 2004 05:00
Initial Analysis
Oct 10, 2017 01:29
CVE Modified
Oct 12, 2018 21:30
CVE Modified
Apr 02, 2020 13:14
Modified Analysis
May 14, 2024 01:18
CVE Modified
Nov 20, 2024 23:35
CVE Modified