vendor:
Outlook Express
by:
SecurityFocus
7.5
CVSS
HIGH
Address Book Misleading Entry
200
CWE
Product Name: Outlook Express
Affected Version From: Outlook Express 5.0
Affected Version To: Outlook Express 6.0
Patch Exists: NO
Related CWE: N/A
CPE: a:microsoft:outlook_express
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2001
Outlook Express Address Book Misleading Entry Vulnerability
An attacker may construct a message header that tricks Address Book into making an entry for an untrusted user under the guise of a trusted one. This is done by sending a message with a misleading 'From:' field. When the message is replied to then Address Book will make an entry which actually replies to the attacker.
Mitigation:
Users should be aware of the potential for malicious emails to be sent with misleading headers. It is also recommended that users do not reply to emails from unknown sources.