PT-2020-1738 · Microsoft · Outlook
Published
2020-02-11
·
Updated
2020-02-13
·
CVE-2020-0696
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook (affected versions not specified)
Description
A security feature bypass issue exists when Microsoft Outlook improperly handles the parsing of URI formats. This can allow a remote attacker to bypass existing security restrictions, redirect a user to a malicious URI, and potentially execute malicious code when combined with other vulnerabilities. The bypass by itself does not enable arbitrary code execution but can be exploited in conjunction with another vulnerability, such as a remote code execution vulnerability, to run arbitrary code. An attacker would need to convince a user to open a specially crafted URI with an affected version of Microsoft Outlook.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Outlook