Information disclosure in Microsoft Outlook and Microsoft Office - CVE-2020-1493

 

Information disclosure in Microsoft Outlook and Microsoft Office - CVE-2020-1493

Published: August 11, 2020 / Updated: September 1, 2020


Vulnerability identifier: #VU45551
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1493
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users.


Affected software

Microsoft Outlook
Microsoft Office

How to mitigate CVE-2020-1493

Install updates from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins