PT-2013-4730 · Microsoft · Outlook

Alexander Klink

·

Publicado

2013-11-12

·

Atualizado

2021-08-30

·

CVE-2013-3905

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Outlook versions 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT
Description The issue allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message. An attacker who successfully exploited this issue could ascertain system information, such as the IP address and open TCP ports, from the target system and other systems that share the network with the target system.
Recommendations For Microsoft Outlook versions 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT, at the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3905

Produtos afetados

Outlook