Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2020-1493

CVE-2020-1493, sévérité medium (CVSS 5.5) : 3 apps suivies concernées, toutes corrigées ou à statut indéterminable en version courante.

Gravité (CVSS)
5.5

Échelle NVD

Exploitation
7.3 %

EPSS, prédiction à 30 jours

Apps suivies
3
Encore exposées
0

EN An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users.
To exploit this vulnerability, an attacker would have to attach a file as a link to an email. The email could then be shared with individuals that should not have access to the files, ignoring the default organizational setting.
The security update addresses the vulnerability by correcting how Outlook handles file attachment links.

Vecteur d'attaque : Local Aucun privilège requis
Voir le vecteur CVSS brut
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS 7.30% au-dessus de la médiane percentile 93.9%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

Configurations CPE vulnérables (10)
Vendor Produit Versions
microsoft office
Toutes plateformes (wildcard)
-
microsoft office
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
microsoft outlook
Toutes plateformes (wildcard)
-
Voir sur NVD ↗ Advisory · portal.msrc.microsoft.com