Unrated severityNVD Advisory· Published Jul 15, 2019· Updated Aug 4, 2024
CVE-2019-1084
CVE-2019-1084
Description
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
Affected products
14- Microsoft/Mail and Calendarv5Range: unspecified
- Range: 2010 Service Pack 3
- Microsoft/Microsoft Exchange Server 2013v5Range: Cumulative Update 23
- Microsoft/Microsoft Exchange Server 2016v5Range: Cumulative Update 12
- Microsoft/Microsoft Exchange Server 2019v5Range: Cumulative Update 1
- Microsoft/Microsoft Lyncv5Range: 2013 Service Pack 1 (32-bit)
- Microsoft/Microsoft Lync Basicv5Range: 2013 Service Pack 1 (32-bit)
- Range: 2013 Service Pack 1 (32-bit editions)
- Microsoft/Microsoft Outlookv5Range: 2010 Service Pack 2 (32-bit editions)
- Range: unspecified
- Microsoft/Office 365 ProPlusv5Range: 32-bit Systems
- Microsoft/Outlook for iOSv5Range: unspecified
- Range: 2016 (32-bit)
- Range: 2016 (32-bit)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1084mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.