#VU16845 Information disclosure in Microsoft Exchange Server - CVE-2019-0588
Published: January 8, 2019 / Updated: March 16, 2019
Microsoft Exchange Server
Microsoft
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to an error when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended. A remote attacker can gain access to potentially sensitive information.