CVE-2019-1084
Summary
| CVE | CVE-2019-1084 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-15 19:15:00 UTC |
| Updated | 2020-05-04 14:14:00 UTC |
| Description | An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Exchange Server | 2010 | sp2 | All | All |
| Application | Microsoft | Exchange Server | 2013 | cumulative_update_23 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_1 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_12 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_13 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_2 | All | All |
| Application | Microsoft | Exchange Server | 2010 | sp2 | All | All |
| Application | Microsoft | Exchange Server | 2013 | cumulative_update_23 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_1 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_12 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_13 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_2 | All | All |
| Application | Microsoft | Lync | 2013 | sp1 | All | All |
| Application | Microsoft | Lync | 2013 | sp1 | All | All |
| Application | Microsoft | Lync Basic | 2013 | sp1 | All | All |
| Application | Microsoft | Lync Basic | 2013 | sp1 | All | All |
| Application | Microsoft | Mail And Calendar | - | All | All | All |
| Application | Microsoft | Mail And Calendar | - | All | All | All |
| Application | Microsoft | Office | 2010 | sp2 | All | All |
| Application | Microsoft | Office | 2013 | sp1 | All | All |
| Application | Microsoft | Office | 2016 | All | All | All |
| Application | Microsoft | Office | 2016 | All | All | All |
| Application | Microsoft | Office | 2019 | All | All | All |
| Application | Microsoft | Office | 2019 | All | All | All |
| Application | Microsoft | Office | 2010 | sp2 | All | All |
| Application | Microsoft | Office | 2013 | sp1 | All | All |
| Application | Microsoft | Office | 2016 | All | All | All |
| Application | Microsoft | Office | 2016 | All | All | All |
| Application | Microsoft | Office | 2019 | All | All | All |
| Application | Microsoft | Office | 2019 | All | All | All |
| Application | Microsoft | Office 365 Proplus | - | All | All | All |
| Application | Microsoft | Office 365 Proplus | - | All | All | All |
| Application | Microsoft | Outlook | - | All | All | All |
| Application | Microsoft | Outlook | 2013 | sp1 | All | All |
| Application | Microsoft | Outlook | 2016 | All | All | All |
| Application | Microsoft | Outlook | 2016 | All | All | All |
| Application | Microsoft | Outlook | - | All | All | All |
| Application | Microsoft | Outlook | 2013 | sp1 | All | All |
| Application | Microsoft | Outlook | 2016 | All | All | All |
| Application | Microsoft | Outlook | 2016 | All | All | All |
| Application | Microsoft | Skype For Business | 2016 | All | All | All |
| Application | Microsoft | Skype For Business | 2016 | All | All | All |
| Application | Microsoft | Skype For Business Basic | 2016 | All | All | All |
| Application | Microsoft | Skype For Business Basic | 2016 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1084 | MISC | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.