Description
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-9665 | An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'. |
References
History
No history.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2024-08-04T18:06:31.581Z
Reserved: 2018-11-26T00:00:00.000Z
Link: CVE-2019-1084
No data.
Status : Modified
Published: 2019-07-15T19:15:17.873
Modified: 2024-11-21T04:35:59.043
Link: CVE-2019-1084
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD