CVE-2000-0342 EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 3.5% (pctl 89)
Patch early
A public exploit exists.
Description
Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| EPSS | 3.45% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-59 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2000-04-28 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| qualcomm | eudora |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Qualcomm Eudora 6.0.1/6.1.1 - Attachment LaunchProtect Warning Bypass (1) | 2003-11-25 |
| exploit-db | Qualcomm Eudora 6.0.1/6.1.1 - Attachment LaunchProtect Warning Bypass (2) | 2003-11-25 |
| exploit-db | Qualcomm Eudora 5.2.1/6.0 - File Attachment Spoofing Variant | 2003-05-22 |
| exploit-db | Qualcomm Eudora 4.2/4.3 - Warning Message Circumvention | 2000-04-28 |
References
- http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077
- http://www.peacefire.org/security/stealthattach/explanation.html
- http://www.securityfocus.com/bid/1157
- http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077
- http://www.peacefire.org/security/stealthattach/explanation.html
- http://www.securityfocus.com/bid/1157
→ the Explorer · watch your stack · NVD