CVE-2020-16949MediumCVSS 4.7
Microsoft Outlook Denial of Service Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could cause a remote denial of service against a system. Exploitation of the vulnerability requires that a specially crafted email be sent to a vulnerable Outlook server. The security update addresses the vulnerability by correcting how Microsoft Outlook handles objects in memory.
🎯 Affected products11
- Microsoft 365 Apps for Enterprise for 32-bit Systems
- Microsoft 365 Apps for Enterprise for 64-bit Systems
- Microsoft Office 2019 for 32-bit editions
- Microsoft Office 2019 for 64-bit editions
- Microsoft Outlook 2010 Service Pack 2 (32-bit editions)
- Microsoft Outlook 2010 Service Pack 2 (64-bit editions)
- Microsoft Outlook 2013 RT Service Pack 1
- Microsoft Outlook 2013 Service Pack 1 (32-bit editions)
- Microsoft Outlook 2013 Service Pack 1 (64-bit editions)
- Microsoft Outlook 2016 (32-bit edition)
- Microsoft Outlook 2016 (64-bit edition)
✅ Remediation
KBClick to Run (Security Update) KB4486671 (Security Update) KB4484524 (Security Update) KB4486663 (Security Update)
🔗 References (4)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-16949
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=4eb19021-9535-46f3-afe6-058aedf76622
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=044d73d7-49c3-48ce-bfc9-d09cdfc7ba3a
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=7bec93cf-6288-449b-a787-e30f7ab48013