An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Exchange | — | Download and install Microsoft KB4509408Download and install Microsoft KB4509409 | Aug 10, 2023 | Jul 15, 2019 |
| Microsoft Office | — | Upgrade to the latest version of Microsoft Office | Aug 13, 2020 | Jul 15, 2019 |
| Msft | — | Security Update for Microsoft Outlook 2010 (KB4475509) 32-Bit EditionSecurity Update For Exchange Server 2013 CU23 (KB4509409)Security Update for Microsoft Office 2013 (KB4464558) 32-Bit EditionSecurity Update for Microsoft Office 2013 (KB4464558) 64-Bit EditionSecurity Update for Microsoft Outlook 2013 (KB4464592) 32-Bit EditionSecurity Update for Skype for Business 2015 (KB4475519) 32-Bit EditionSecurity Update for Microsoft Outlook 2010 (KB4475509) 64-Bit EditionSecurity Update for Skype for Business 2015 (KB4475519) 64-Bit EditionUpdate Rollup 29 for Exchange Server 2010 Service Pack 3 (KB4509410)Security Update for Microsoft Outlook 2013 (KB4464592) 64-Bit Edition | Jul 9, 2019 | Jul 9, 2019 |
| Office For Mac | — | Upgrade to Office for Mac version 16.16.12Upgrade to Office for Mac version 16.27.0 | Jul 9, 2019 | Jul 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub