CVE-1999-1164: Medium severity Microsoft Outlook Express vulnerability
Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
At the mail gateway/POP3/IMAP server or mail proxy, detect and drop or reject incoming messages that contain multiple identical X-UIDL headers so such messages never reach Microsoft Outlook or Outlook Express and cannot cause the client to hang.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1164?
CVE-1999-1164 is classified as a denial of service vulnerability.
How does CVE-1999-1164 affect Microsoft Outlook clients?
CVE-1999-1164 allows remote attackers to hang Microsoft Outlook clients by sending multiple email messages with the same X-UIDL headers.
Which versions of Microsoft Outlook are affected by CVE-1999-1164?
CVE-1999-1164 affects Microsoft Outlook 97, 98, and 2000, as well as Microsoft Outlook Express.
How can I mitigate the impact of CVE-1999-1164?
To mitigate CVE-1999-1164, consider limiting the number of email messages accepted from remote senders.
Is there a patch available for CVE-1999-1164?
There is no specific patch for CVE-1999-1164; it is recommended to upgrade to a later version of Microsoft Outlook.