PT-2020-3794 · Microsoft · Outlook

CVE-2020-1493

·

Published

2020-08-11

·

Updated

2024-07-03

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Outlook versions prior to the fixed version
Description: An information disclosure issue exists when attaching files to Outlook messages, potentially allowing users to share attached files with anonymous users, even when they should be restricted to specific users. This could be exploited by an attacker sending an email with a file attached as a link, thereby ignoring default organizational settings. The issue arises from how Outlook handles file attachment links.
Recommendations: To resolve the issue, apply the security update that corrects how Outlook handles file attachment links. As a temporary workaround, consider avoiding the use of file attachment links in Outlook until the update is applied. Restrict access to sensitive files to minimize the risk of exploitation.

Exploit

Fix

Insecure Storage of Sensitive Information

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04156
CVE-2020-1493
ZDI-20-999

Affected Products

Outlook