SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1493

An information disclosure vulnerability exists when attaching files to Outlook messages.

MEDIUM 5.5EPSS 7.30%

Does this matter?

Lower severity and a low EPSS score (7.30%). Track it; it rarely justifies an emergency change on its own.

Description

An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users. To exploit this vulnerability, an attacker would have to attach a file as a link to an email. The email could then be shared with individuals that should not have access to the files, ignoring the default organizational setting. The security update addresses the vulnerability by correcting how Outlook handles file attachment links.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
7.30% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-922
Affected
microsoft/365 apps · microsoft/office · microsoft/outlook
Source
secure@microsoft.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.