CVE-2019-1084 - CVE House
Back to Database
Status published Medium CVE-2019-1084

An information disclosure vulnerability exists when Exchange allows creation of...

Vulnerability Description

An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-1084

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Microsoft Exchange Server, Microsoft Outlook, Microsoft Office, Microsoft Lync, Microsoft Lync Basic, Microsoft Outlook for Android, Skype for Business, Skype for Business Basic, Office 365 ProPlus, Microsoft Exchange Server 2016, Microsoft Exchange Server 2019, Microsoft Exchange Server 2013, Mail and Calendar, Outlook for iOS
Vulnerable Versions:
2010 Service Pack 3, 2010 Service Pack 2 (32-bit editions), 2010 Service Pack 2 (64-bit editions), 2016 (32-bit edition), 2016 (64-bit edition), 2013 Service Pack 1 (32-bit editions), 2013 Service Pack 1 (64-bit editions), 2013 RT Service Pack 1, 2016 for Mac, 2019 for 32-bit editions, 2019 for 64-bit editions, 2019 for Mac, 2013 Service Pack 1 (32-bit), 2013 Service Pack 1 (64-bit), unspecified, 2016 (32-bit), 2016 (64-bit), 32-bit Systems, 64-bit Systems, Cumulative Update 12, Cumulative Update 13, Cumulative Update 1, Cumulative Update 2, Cumulative Update 23

Timeline

Official Publish: July 15th, 2019
Last Modified: August 4th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.