Microsoft Outlook 2000 0/98 0/Express 5.5 - Concealed Attachment

EDB-ID:

20571

CVE:





Platform:

Windows

Date:

2001-01-17


source: https://www.securityfocus.com/bid/2260/info

Versions of MS Outlook are vulnerable to receiving a hidden, potentially hostile attachment. An arbitrary string of characters, supplied by the sender to the 'subject:' field, will be received and interpreted by vulnerable versions of Outlook as an attachment to the message. If this string is properly constructed, it can be executable and capable of performing hostile actions on the vulnerable host.

This can also be used to circumvent Outlook's dangerous file security feature. 

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/20571.zip