CVE-2001-0660

Microsoft Exchange <5.5.SP4 - Info Disclosure

Title source: llm
STIX 2.1

Description

Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that processes the global address list (GAL).

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3301
Patch, Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/support/kb/articles/Q307/1/95.ASP
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7089

Scores

EPSS 0.2199
EPSS Percentile 97.4%

Details

Status published
Products (1)
microsoft/exchange_server < 5.5
Published Oct 30, 2001
Tracked Since Feb 18, 2026