Microsoft Exchange Server CVE-2019-1084 Information Disclosure Vulnerability
BID:108929
Info
Microsoft Exchange Server CVE-2019-1084 Information Disclosure Vulnerability
| Bugtraq ID: | 108929 |
| Class: | Design Error |
| CVE: |
CVE-2019-1084 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2019 12:00AM |
| Updated: | Jul 09 2019 12:00AM |
| Credit: | Jonathan Birch of Microsoft Corporation |
| Vulnerable: |
Microsoft Skype for Business Basic 2016 (64-bit) 0 Microsoft Skype for Business Basic 2016 (32-bit) 0 Microsoft Skype for Business 2016 (64-bit) 0 Microsoft Skype for Business 2016 (32-bit) 0 Microsoft Outlook for iOS 0 Microsoft Outlook for Android 0 Microsoft Outlook 2016 (64-bit editions) Microsoft Outlook 2016 (32-bit editions) Microsoft Outlook 2013 Service Pack 1 (64-bit editions) 0 Microsoft Outlook 2013 Service Pack 1 (32-bit editions) 0 Microsoft Outlook 2010 (64-bit editions) Service Pack 2 Microsoft Outlook 2010 (32-bit editions) Service Pack 2 Microsoft Office 365 ProPlus for 64-bit Systems 0 Microsoft Office 365 ProPlus for 32-bit Systems 0 Microsoft Office 2019 for Mac 0 Microsoft Office 2019 for 64-bit editions 0 Microsoft Office 2019 for 32-bit editions 0 Microsoft Office 2016 for Mac 0 Microsoft Office 2016 (64-bit edition) 0 Microsoft Office 2016 (32-bit edition) 0 Microsoft Office 2013 Service Pack 1 (64-bit editions) Microsoft Office 2013 Service Pack 1 (32-bit editions) Microsoft Office 2013 RT Service Pack 1 0 Microsoft Mail and Calendar 0 Microsoft Lync Basic 2013 (64-bit) SP1 Microsoft Lync Basic 2013 (32-bit) SP1 Microsoft Lync 2013 (64-bit) SP1 Microsoft Lync 2013 (32-bit) SP1 Microsoft Exchange Server 2019 Cumulative Update 2 Microsoft Exchange Server 2019 Cumulative Update 1 Microsoft Exchange Server 2016 Cumulative Update 13 Microsoft Exchange Server 2016 Cumulative Update 12 Microsoft Exchange Server 2013 Cumulative Update 23 Microsoft Exchange Server 2010 SP3 |
| Not Vulnerable: | |
Discussion
Microsoft Exchange Server CVE-2019-1084 Information Disclosure Vulnerability
Microsoft Exchange Server is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Microsoft Exchange Server is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
Exploit / POC
Microsoft Exchange Server CVE-2019-1084 Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Exchange Server CVE-2019-1084 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Exchange Server CVE-2019-1084 Information Disclosure Vulnerability
References:
References:
- Microsoft Exchange Home Page (Microsoft)
- Microsoft Homepage (Microsoft)
- CVE-2019-1084 | Microsoft Exchange Information Disclosure Vulnerability (Microsoft)