CVE-2000-0216: Medium severity Microsoft Outlook vulnerability

Published Feb 29, 2000
·
Updated

Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.

Affected Software

3 affected components
Microsoft Outlook
Microsoft Exchange Server
Microsoft Windows Messaging

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable automatic sending of Read Receipt and Delivery Receipt responses in Outlook so the client does not automatically reply to read/delivery requests.

    Microsoft Outlook Automatic Read Receipt and Delivery Receipt responses = disabled
  2. Configuration

    Configure Exchange Server to disable automatic generation or automatic forwarding of Read Receipt and Delivery Receipt responses to prevent mass automated replies.

    Microsoft Exchange Server Automatic Read Receipt and Delivery Receipt responses = disabled
  3. Configuration

    Disable automatic sending of Read Receipt and Delivery Receipt responses in Windows Messaging to prevent automatic replies from being generated.

    Microsoft Windows Messaging Automatic Read Receipt and Delivery Receipt responses = disabled

Event History

Feb 29, 2000
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Mar 22, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0216?

CVE-2000-0216 is classified as a moderate severity vulnerability that can lead to denial of service in email systems.

2

How can an organization fix CVE-2000-0216?

To mitigate CVE-2000-0216, organizations should apply patches for Microsoft Outlook, Exchange Server, and Windows Messaging as recommended by Microsoft.

3

What type of attack does CVE-2000-0216 allow?

CVE-2000-0216 allows attackers to flood a mail system with false Read Receipt responses by forging requests sent to distribution lists.

4

Which Microsoft products are affected by CVE-2000-0216?

Microsoft Outlook, Microsoft Exchange Server, and Microsoft Windows Messaging are the affected products in CVE-2000-0216.

5

Is user action required for CVE-2000-0216 exploitation?

Yes, CVE-2000-0216 requires that email clients automatically respond to Read Receipt requests without user intervention, making them vulnerable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203