PT-2020-3794 · Microsoft · Outlook
Published
2020-08-11
·
Updated
2024-07-03
·
CVE-2020-1493
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Microsoft Outlook versions prior to the fixed version
Description:
An information disclosure issue exists when attaching files to Outlook messages, potentially allowing users to share attached files with anonymous users, even when they should be restricted to specific users. This could be exploited by an attacker sending an email with a file attached as a link, thereby ignoring default organizational settings. The issue arises from how Outlook handles file attachment links.
Recommendations:
To resolve the issue, apply the security update that corrects how Outlook handles file attachment links.
As a temporary workaround, consider avoiding the use of file attachment links in Outlook until the update is applied.
Restrict access to sensitive files to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Outlook