ZeroHour

CVE-2019-1084

CVSS 3.0
6.5 medium
EPSS
5%p92
Published
()
Modified
Description

An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.

Vendors
microsoft
Products
exchange server, lync, lync basic, mail and calendar, office, office 365 proplus, outlook, skype for business, skype for business basic
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.