← Back

CVE-2019-1204

nvd nist
Published: Aug 14, 2019Modified: Feb 20, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB). To exploit the vulnerability, the attacker could send a specially crafted email to a victim. Outlook would then attempt to open a pre-configured message store contained in the email upon receipt of the email. This update addresses the vulnerability by ensuring Office fully validates incoming email formatting before processing message content.

Affected (6)

3 products
Office
Office 365 Proplus
Outlook
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Version 2019
All versions
Microsoft
Version 2010 sp2
Version 2013 sp1
Version 2013 sp1
Version 2016

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.