First published: Tue Jun 12 2007(Updated: )
The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server 2003 | ||
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows Server 2003 | =sp1 | |
Microsoft Windows Server 2003 | =sp1 | |
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Outlook Express | =6.0 | |
Microsoft Windows Vista | =gold | |
Microsoft Windows Vista | =gold | |
Microsoft Outlook.com |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2227 is considered a high severity vulnerability due to its potential for information disclosure from cross-domain attacks.
CVE-2007-2227 affects Microsoft Outlook Express 6 and Windows Mail in Windows Vista, allowing unauthorized access to sensitive information.
To fix CVE-2007-2227, users should ensure they have installed security updates provided by Microsoft for Outlook Express and Windows Mail.
CVE-2007-2227 demonstrates a cross-domain attack that exploits improper handling of Content-Disposition notifications.
Only Microsoft Outlook Express 6 is specifically mentioned as vulnerable to CVE-2007-2227, while other software versions are not affected.