First published: Fri Sep 07 2001(Updated: )
The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Norton Antivirus | =2.5 | |
Microsoft Exchange Server | =2000 | |
Microsoft Exchange Server | =2000-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1099 is considered a moderate security vulnerability due to the potential for remote attackers to discover sensitive file paths.
To fix CVE-2001-1099, update Norton AntiVirus to a newer version that addresses this vulnerability.
CVE-2001-1099 specifically affects Norton AntiVirus for Microsoft Exchange 2000 version 2.5.
Yes, if exploited, CVE-2001-1099 could potentially allow further attacks by revealing the victim's INBOX file path.
A workaround for CVE-2001-1099 may include disabling the automatic processing of attachments in Norton AntiVirus.