CVE-2019-1084
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
Published:Jul 15, 2019
Last Modified:Nov 21, 2024
EPS:Jul 15, 2019
EPSS Score:0.06416
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Microsoft
Product
Exchange Server
Microsoft
Exchange Server
Vendor
Microsoft
Product
Lync
Microsoft
Lync
Vendor
Microsoft
Product
Lync Basic
Microsoft
Lync Basic
Vendor
Microsoft
Product
Mail And Calendar
Microsoft
Mail And Calendar
Vendor
Microsoft
Product
Office
Microsoft
Office
Vendor
Microsoft
Product
Office 365 Proplus
Microsoft
Office 365 Proplus
Vendor
Microsoft
Product
Outlook
Microsoft
Outlook
Vendor
Microsoft
Product
Skype For Business
Microsoft
Skype For Business
Vendor
Microsoft
Product
Skype For Business Basic
Microsoft
Skype For Business Basic
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
