Cache Bypass Vulnerability in Outlook 98/2000 and Outlook Express 4.x/5.x

HIGH (7.5) Patch Available Patch Patch

Threat Intelligence

Low Risk
EPSS Score: 5.84% chance of exploitation (percentile: 90%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

Microsoft Outlook 98 and 2000, as well as Outlook Express 4.0x and 5.0x, are email clients that allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache. This vulnerability can be exploited by sending a maliciously crafted HTML message to an affected user, potentially leading to unauthorized access to sensitive data.

Am I affected?

You're affected if you use Microsoft Outlook 98 or 2000, or Outlook Express 4.0x or 5.0x. Check with: file /i *.html (Windows command) or grep -r "HTML" outlook*.exe (command-line search in executable files).

Note: This vulnerability is specific to these versions of the software and not applicable to other Microsoft products.

Affected Products

Microsoft / Outlook 98/2000, Outlook Express 4.0x/5.0x

How to fix

Upgrade to a newer version of Outlook, such as Outlook 2002 or later.
- Apply the patch from Microsoft's security advisory (http://www.cert.org/advisories/CA-2000-14.html).
- Immediate mitigations:
- Use a reputable antivirus program to scan for malicious attachments and emails.
- Be cautious when opening HTML files or attachments from unknown sources.