6.5

CVE-2019-1084

An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftExchange Server Version2010 Updatesp2
MicrosoftExchange Server Version2013 Updatecumulative_update_23
MicrosoftExchange Server Version2016 Updatecumulative_update_1
MicrosoftExchange Server Version2016 Updatecumulative_update_12
MicrosoftExchange Server Version2016 Updatecumulative_update_13
MicrosoftExchange Server Version2016 Updatecumulative_update_2
MicrosoftLync Version2013 Updatesp1
MicrosoftLync Basic Version2013 Updatesp1
MicrosoftOffice Version2010 Updatesp2
MicrosoftOffice Version2013 Updatesp1
MicrosoftOffice Version2016
MicrosoftOffice Version2016 SwPlatformmac_os
MicrosoftOffice Version2019
MicrosoftOffice Version2019 SwPlatformmacos
MicrosoftOutlook Version- SwPlatformiphone_os
MicrosoftOutlook Version2013 Updatesp1
MicrosoftOutlook Version2016
MicrosoftOutlook Version2016 SwPlatformandroid
MicrosoftSkype For Business Version2016
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.82% 0.917
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.