VYPR
Medium severity6.5NVD Advisory· Published Jan 8, 2019· Updated Jun 17, 2026

CVE-2019-0588

CVE-2019-0588

Description

An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange Information Disclosure Vulnerability." This affects Microsoft Exchange Server.

Affected products

7
  • cpe:2.3:a:microsoft:exchange_server:2010:sp3_rollup25:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:microsoft:exchange_server:2010:sp3_rollup25:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:2013:cumulative_update_21:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 2010 Service Pack 3 Update Rollup 25

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.