Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2019-1204

CVE-2019-1204, sévérité medium (CVSS 4.3) : 3 apps suivies concernées, toutes corrigées ou à statut indéterminable en version courante.

Gravité (CVSS)
4.3

Échelle NVD

Exploitation
4.4 %

EPSS, prédiction à 30 jours

Apps suivies
3
Encore exposées
0

EN An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB).
To exploit the vulnerability, the attacker could send a specially crafted email to a victim. Outlook would then attempt to open a pre-configured message store contained in the email upon receipt of the email.
This update addresses the vulnerability by ensuring Office fully validates incoming email formatting before processing message content.

Vecteur d'attaque : Réseau Aucun privilège requis
Voir le vecteur CVSS brut
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS 4.42% au-dessus de la médiane percentile 90.7%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

Configurations CPE vulnérables (10)
Vendor Produit Versions
microsoft office
Toutes plateformes (wildcard)
-
microsoft office
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
Voir sur NVD ↗ Advisory · portal.msrc.microsoft.com