PT-2020-1738 · Microsoft · Outlook

Published

2020-02-11

·

Updated

2020-02-13

·

CVE-2020-0696

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Outlook (affected versions not specified)
Description A security feature bypass issue exists when Microsoft Outlook improperly handles the parsing of URI formats. This can allow a remote attacker to bypass existing security restrictions, redirect a user to a malicious URI, and potentially execute malicious code when combined with other vulnerabilities. The bypass by itself does not enable arbitrary code execution but can be exploited in conjunction with another vulnerability, such as a remote code execution vulnerability, to run arbitrary code. An attacker would need to convince a user to open a specially crafted URI with an affected version of Microsoft Outlook.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00978
CVE-2020-0696

Affected Products

Outlook