CVE-2000-0036: Medium severity Microsoft Outlook Express vulnerability
Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure Outlook Express 5 (Macintosh) to prompt before downloading or saving attachments; disable automatic downloading of attachments for HTML mail so the user is prompted before attachments are saved.
Outlook Express 5 for Macintosh download_attachments_automatically = false - Configuration
Disable rendering of HTML mail or configure the client to display messages as plain text to prevent automatic processing of HTML content and associated attachments.
Outlook Express 5 for Macintosh display_html_mail = disabled - Compensating control
Implement mail gateway/server controls to block or strip HTML email or to remove/scan attachments from HTML mail before delivery to users, preventing automatic delivery of attachments in HTML messages.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0036?
The severity of CVE-2000-0036 is considered medium due to the risk of unauthorized file downloads.
How do I fix CVE-2000-0036?
To fix CVE-2000-0036, users should upgrade to a patched version of Outlook Express or Internet Explorer that addresses this vulnerability.
What are the implications of CVE-2000-0036?
CVE-2000-0036 allows attackers to exploit Outlook Express to download attachments without user consent, potentially leading to malware infection.
Who is affected by CVE-2000-0036?
Users of Outlook Express version 5.0 for Mac OS and Internet Explorer version 4.5 for Macintosh are affected by CVE-2000-0036.
Is there a workaround for CVE-2000-0036?
A possible workaround for CVE-2000-0036 includes disabling HTML mail or using an alternative email client until the software can be updated.