Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Outlook Express BCC: Recipient Disclosure

Medium

Synopsis

The remote email client is vulnerable to a flaw where the 'BCC' address is not hidden.

Description

The remote host is using Outlook Express version 6.00 or 6.00 SP1. It is reported that the effectiveness of the BCC: field in these versions cannot be trusted. People receiving the mail through the To: and CC: fields can find the invisible receipients by opening the mail in a text editor.

Solution

Upgrade or patch according to vendor recommendations.