Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6qr8-95p4-28hw

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."

Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."

EPSS

Процентиль: 94%
0.14651
Средний

Дефекты

CWE-200

Связанные уязвимости

nvd
около 12 лет назад

Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."

EPSS

Процентиль: 94%
0.14651
Средний

Дефекты

CWE-200