First published: Thu May 03 2001(Updated: )
HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | <=5.5 | |
Internet Explorer | =5.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0154 is considered a critical vulnerability because it allows attackers to execute potentially malicious attachments via HTML emails.
To mitigate CVE-2001-0154, it is recommended to upgrade to a newer version of Internet Explorer that does not have this vulnerability.
CVE-2001-0154 affects Internet Explorer versions 5.5 and earlier, including specific version 5.01.
Attackers exploit CVE-2001-0154 by using unusual MIME types in HTML email attachments to execute malicious files.
To ensure you're not vulnerable to CVE-2001-0154, avoid using outdated versions of Internet Explorer and consider using a more secure web browser.