An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: microsoft
Published: 2019-07-15T18:56:21
Updated: 2024-08-04T18:06:31.581Z
Reserved: 2018-11-26T00:00:00
Link: CVE-2019-1084
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-07-15T19:15:17.873
Modified: 2024-11-21T04:35:59.043
Link: CVE-2019-1084
Redhat
No data.