Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2019-1204

CVE-2019-1204, medium severity (CVSS 4.3): 3 tracked apps concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
4.3

NVD scale

Exploitation
4.4 %

EPSS, predicted over 30 days

Tracked apps
3
Still exposed
0

An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB).
To exploit the vulnerability, the attacker could send a specially crafted email to a victim. Outlook would then attempt to open a pre-configured message store contained in the email upon receipt of the email.
This update addresses the vulnerability by ensuring Office fully validates incoming email formatting before processing message content.

Attack vector : Network No privileges required
Show raw CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS 4.42% above median percentile 90.7%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (10)
Vendor Product Versions
microsoft office
All platforms (wildcard)
-
microsoft office
All platforms (wildcard)
-
microsoft outlook
All platforms (wildcard)
-
microsoft outlook
All platforms (wildcard)
-
microsoft outlook
All platforms (wildcard)
-
microsoft outlook
All platforms (wildcard)
-
microsoft outlook
All platforms (wildcard)
-
microsoft outlook
All platforms (wildcard)
-
microsoft outlook
All platforms (wildcard)
-
microsoft outlook
All platforms (wildcard)
-
View on NVD ↗ Advisory · portal.msrc.microsoft.com