5.5

CVE-2020-1493

Microsoft Outlook Information Disclosure Vulnerability

An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users.
To exploit this vulnerability, an attacker would have to attach a file as a link to an email. The email could then be shared with individuals that should not have access to the files, ignoring the default organizational setting.
The security update addresses the vulnerability by correcting how Outlook handles file attachment links.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ 365 Apps Version - SwEdition enterprise
Microsoft ≫ Office Version 2019 SwPlatform -
Microsoft ≫ Outlook Version 2010 Update sp2
Microsoft ≫ Outlook Version 2013 Update sp1
Microsoft ≫ Outlook Version 2013 Update sp1 SwEdition rt
Microsoft ≫ Outlook Version 2016
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.3% 0.936
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-922 Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

http://packetstormsecurity.com/files/169960/Microsoft-Outlook-2019-16.0.12624.20424-Out-Of-Bounds-Read.html
Third Party Advisory
VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1493
Patch
Vendor Advisory