ADV190014High

Microsoft Live Accounts Elevation of Privilege Vulnerability

Published
August 13, 2019
Last Modified
—

🔗 CVE IDs covered (1)

ADV190014 · pending

📋 Description

An elevation of privilege vulnerability exists in Outlook Web Access (OWA) regarding a possible unsigned token. An attacker who successfully exploited this vulnerability could have access to another person's email inbox. To exploit this vulnerability, an attacker would first have to replace an unsigned token with a different one. This vulnerability has been mitigated for all users' Microsoft Live accounts.

🎯 Affected products3

  • Microsoft Exchange Online
  • Microsoft Office 365
  • Outlook.com