CVE-2018-8305High

Windows Mail Client Information Disclosure Vulnerability

Published
July 10, 2018
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists in Windows Mail Client when a message is opened. This vulnerability could potentially result in the disclosure of sensitive information to a malicious site. To exploit the vulnerability, an attacker would have to send a malicious email to a user and convince the user to open the email. A connection to a remote server could then be automatically initiated, depending on the URL contained in the malicious email, Windows Mail Client could fall back to initiating a web request to a remote server, disclosing the external IP of the user's system. The security update addresses the vulnerability by correcting how Windows Mail Client processes embedded URLs.

🎯 Affected products1

  • Mail, Calendar, and People in Windows 8.1 App Store

🔗 References (1)