CVE-2000-0216: Medium severity Microsoft Outlook vulnerability
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable automatic sending of Read Receipt and Delivery Receipt responses in Outlook so the client does not automatically reply to read/delivery requests.
Microsoft Outlook Automatic Read Receipt and Delivery Receipt responses = disabled - Configuration
Configure Exchange Server to disable automatic generation or automatic forwarding of Read Receipt and Delivery Receipt responses to prevent mass automated replies.
Microsoft Exchange Server Automatic Read Receipt and Delivery Receipt responses = disabled - Configuration
Disable automatic sending of Read Receipt and Delivery Receipt responses in Windows Messaging to prevent automatic replies from being generated.
Microsoft Windows Messaging Automatic Read Receipt and Delivery Receipt responses = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0216?
CVE-2000-0216 is classified as a moderate severity vulnerability that can lead to denial of service in email systems.
How can an organization fix CVE-2000-0216?
To mitigate CVE-2000-0216, organizations should apply patches for Microsoft Outlook, Exchange Server, and Windows Messaging as recommended by Microsoft.
What type of attack does CVE-2000-0216 allow?
CVE-2000-0216 allows attackers to flood a mail system with false Read Receipt responses by forging requests sent to distribution lists.
Which Microsoft products are affected by CVE-2000-0216?
Microsoft Outlook, Microsoft Exchange Server, and Microsoft Windows Messaging are the affected products in CVE-2000-0216.
Is user action required for CVE-2000-0216 exploitation?
Yes, CVE-2000-0216 requires that email clients automatically respond to Read Receipt requests without user intervention, making them vulnerable.