CVE-2003-0007

Microsoft Outlook 2002 - Information Disclosure via V1 Exchange Server Security Certificate Handling

Title source: llm
STIX 2.1

Description

Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/11133
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6667

Scores

EPSS 0.0391
EPSS Percentile 89.3%

Details

Status published
Products (1)
microsoft/outlook 2002 (3 CPE variants)
Published Feb 07, 2003
Tracked Since Feb 18, 2026