vendor:
Outlook
by:
Unknown
5.5
CVSS
MEDIUM
Security policy bypass
693
CWE
Product Name: Outlook
Affected Version From: Microsoft Outlook 2003
Affected Version To: Microsoft Outlook 2003
Patch Exists: NO
Related CWE: Not provided
CPE: a:microsoft:outlook:2003
Platforms Tested: Windows
Unknown
Microsoft Outlook 2003 Security Policy Bypass Vulnerability
By including a base64 encoded image in an email and labeling it in a sufficient manner, it is possible to reference the base64 encoded image, resulting in a policy bypass because the image will be automatically rendered when the email is viewed in Outlook 2003.
Mitigation:
No known mitigation