CVE-2001-0660: Medium severity Microsoft Exchange Server vulnerability
Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that processes the global address list (GAL).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0660?
CVE-2001-0660 is considered a medium severity vulnerability since it allows attackers to enumerate valid email addresses.
How do I fix CVE-2001-0660?
To mitigate CVE-2001-0660, ensure your Microsoft Exchange Server is updated to a patched version and restrict access to the Outlook Web Access functionality.
What software is affected by CVE-2001-0660?
CVE-2001-0660 affects Microsoft Exchange Server 5.5 Service Pack 4 and earlier versions.
Can CVE-2001-0660 be exploited remotely?
Yes, CVE-2001-0660 can be exploited remotely by attackers who access the Outlook Web Access interface.
What are the potential impacts of CVE-2001-0660?
The primary impact of CVE-2001-0660 is the exposure of valid email addresses from the global address list, potentially aiding in further attacks.