← Back

CVE-2019-1084

nvd nist
Published: Jul 15, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.

Affected (22)

9 products
Exchange Server
Lync
Lync Basic
Mail And Calendar
Office
Office 365 Proplus
Outlook
Skype For Business
Skype For Business Basic
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2010 sp2
Version 2013 cumulative_update_23
Version 2016 cumulative_update_12
Version 2016 cumulative_update_13
Version 2016 cumulative_update_1
Version 2016 cumulative_update_2
Version 2013 sp1
Version 2013 sp1
All versions
Microsoft
Version 2010 sp2
Version 2013 sp1
Version 2016
Version 2016
Version 2019
Version 2019
All versions
Microsoft
All versions
Version 2013 sp1
Version 2016
Version 2016
Version 2016
Version 2016

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.