Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-1218

Опубликовано: 13 авг. 2019
Источник: msrc
EPSS Низкий

Описание

Outlook iOS Spoofing Vulnerability

A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim.

The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on the affected systems and run scripts in the security context of the current user.

The security update addresses the vulnerability by correcting how Outlook iOS parses specially crafted email messages.

FAQ

How do I get the update for Outlook for IOS?

  1. Tap the Settings Icon
  2. Tap the iTunes & App Store
  3. Turn on AUTOMATIC DOWNLOADS for Apps

Alternatively

  1. Tap the App Store Icon
  2. Scroll down to find Microsoft Outlook
  3. Tap the Update button

Обновления

ПродуктСтатьяОбновление
Outlook for iOS

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 92%
0.08981
Низкий

Связанные уязвимости

CVSS3: 5.4
nvd
около 6 лет назад

A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim. The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on the affected systems and run scripts in the security context of the current user. The security update addresses the vulnerability by correcting how Outlook iOS parses specially crafted email messages.

github
больше 3 лет назад

A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages, aka 'Outlook iOS Spoofing Vulnerability'.

CVSS3: 5.4
fstec
около 6 лет назад

Уязвимость почтового клиента Microsoft Outlook iOS, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю осуществлять атаки межсайтового выполнения сценариев и оказывать воздействие на целостность защищаемой информации

EPSS

Процентиль: 92%
0.08981
Низкий