CVE-2001-1088 Information
Feb 14, 2021
cve
Description
Microsoft Outlook 8.5 and earlier and Outlook Express 5 and earlier with the \Automatically put people I reply to in my address book\ option enabled do not notify the user when the \Reply-To\ address is different than the \From\ address which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.
Reference
http://support.microsoft.com/default.aspx?scid=kb;EN-US;q234241 http://www.securityfocus.com/archive/1/188752 http://www.securityfocus.com/bid/2823 https://exchange.xforce.ibmcloud.com/vulnerabilities/6655
Share on: