CVE-2016-0138High

Microsoft Outlook Information Disclosure Vulnerability

Published
September 13, 2016
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists in the way that Microsoft Exchange Server parses email messages. The vulnerability could allow an attacker to discover confidential user information that is contained in Microsoft Outlook applications. To exploit the vulnerability, an attacker could use "send as" rights to send a specially crafted message to a user. The security update addresses the vulnerability by correcting how Microsoft Exchange parses certain unstructured file formats.

🎯 Affected products7

  • Microsoft Exchange Server 2007 Service Pack 3
  • Microsoft Exchange Server 2010 Service Pack 3
  • Microsoft Exchange Server 2013 Cumulative Update 12
  • Microsoft Exchange Server 2013 Cumulative Update 13
  • Microsoft Exchange Server 2013 Service Pack 1
  • Microsoft Exchange Server 2016 Cumulative Update 1
  • Microsoft Exchange Server 2016 Cumulative Update 2

✅ Remediation

KB3184736 (Security Update) KB3184728 (Security Update) KB3184711 (Security Update)

🔗 References (5)