5

CVE-2013-3905

Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftOutlook Version2007 Updatesp3
MicrosoftOutlook Version2010 Updatesp1 HwPlatformx64
MicrosoftOutlook Version2010 Updatesp1 SwPlatformx86
MicrosoftOutlook Version2010 Updatesp2 HwPlatformx64
MicrosoftOutlook Version2010 Updatesp2 SwPlatformx86
MicrosoftOutlook Version2013
MicrosoftOutlook Version2013 Update- Edition- SwEdition- SwPlatform- HwPlatformx64
MicrosoftOutlook Version2013 Update- Edition- SwEdition- SwPlatform- HwPlatformx86
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 14.65% 0.942
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.