CVE-2001-0154
Status: ModifiedHigh (7.5)—
HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 11%
- Percentile among all scored CVEs: 96
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://marc.info/?l=bugtraq&m=98596775905044&w=2
- http://securitytracker.com/id?1001197
- http://www.cert.org/advisories/CA-2001-06.html
- http://www.ciac.org/ciac/bulletins/l-066.shtml
- http://www.osvdb.org/7806
- http://www.securityfocus.com/bid/2524
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-020
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6306
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A141
- http://marc.info/?l=bugtraq&m=98596775905044&w=2
- http://securitytracker.com/id?1001197
- http://www.cert.org/advisories/CA-2001-06.html
- http://www.ciac.org/ciac/bulletins/l-066.shtml
- http://www.osvdb.org/7806
- http://www.securityfocus.com/bid/2524
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-020
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6306
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A141
Raw JSON (NVD)
Show
{
"id": "CVE-2001-0154",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2001-05-03T04:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=98596775905044&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1001197",
"source": "cve@mitre.org"
},
{
"url": "http://www.cert.org/advisories/CA-2001-06.html",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ciac.org/ciac/bulletins/l-066.shtml",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/7806",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/2524",
"source": "cve@mitre.org"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-020",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/6306",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A141",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=98596775905044&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1001197",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.cert.org/advisories/CA-2001-06.html",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ciac.org/ciac/bulletins/l-066.shtml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/7806",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/2524",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-020",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/6306",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A141",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly."
},
{
"lang": "es",
"value": "Funcionalidad HTML en Internet Explorer 5.5 y anteriores, que permite al atacante la ejecución de un archivo adjunto. Se consigue gracias al envío de cabeceras MIME inválidas para el adjunto que le permiten disfrazarse como un tipo de archivo no ejecutable. \r\n\r\nEl correo electrónico vía HTML se representa en páginas web que el explorador es capaz de interpretar. Cuando el correo contiene ficheros adjuntos el Explorador también es capaz de abrir la aplicación asociada a los ficheros binarios adjuntos cuyo tipo (extensión de archivo) está definido en las cabeceras MIME. \r\n\r\nSin embargo, existe un defecto en el tipo de tratamiento que es especificado para ciertos tipos MIME sin identificar. Si un atacante crea un correo HTML conteniendo un fichero adjunto ejecutable y le sustituye la información de cabecera MIME por otra, que contiene un tipo de archivo MIME reconocido, provocaría la ejecución automática del adjunto.\r\n\r\nUn atacante podría usar esta vulnerabilidad en cualquiera de estos dos escenarios.\r\n\r\nEl atacante podíra generar un correo electrónico HTML infectado sobre un sitio web ý despues intentar convencer a otro usuario para que los visite. El fichero adjunto sería ejecutado automáticamente simplemente por visualizar la página que muestra la lista de mensajes.\r\n\r\nEn el otro supuesto, el atacante conseguiría su objetivo enviándo directamente el correo HTML a la dirección del ususario que desea infectar.\r\n\r\nEn ambos supuestos la ejecución del adjunto está limitada a los privilegios de sistema que tenga establecidos el ususario."
}
],
"lastModified": "2026-06-16T21:53:46.457",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7BDFCFCB-6E90-4F29-9852-A3099DF05843",
"versionEndIncluding": "5.5"
},
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6219D36E-9E2C-4DC7-8FD5-FAD144A333F6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}