CVE-2018-8305High
Windows Mail Client Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An information disclosure vulnerability exists in Windows Mail Client when a message is opened. This vulnerability could potentially result in the disclosure of sensitive information to a malicious site. To exploit the vulnerability, an attacker would have to send a malicious email to a user and convince the user to open the email. A connection to a remote server could then be automatically initiated, depending on the URL contained in the malicious email, Windows Mail Client could fall back to initiating a web request to a remote server, disclosing the external IP of the user's system. The security update addresses the vulnerability by correcting how Windows Mail Client processes embedded URLs.
🎯 Affected products1
- Mail, Calendar, and People in Windows 8.1 App Store