Description
Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
References (4)
Core 4
Core References
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/1501
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5013
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-046
Patch, Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert
http://www.cert.org/advisories/CA-2000-14.html
Scores
EPSS
0.2231
EPSS Percentile
97.5%
Details
Status
published
Products (7)
microsoft/outlook
97
microsoft/outlook
98
microsoft/outlook
2000
microsoft/outlook_express
4.0
microsoft/outlook_express
4.01
microsoft/outlook_express
5.0
microsoft/outlook_express
5.0.1
Published
Jul 20, 2000
Tracked Since
Feb 18, 2026