CVE-2019-1084
Last modified
CVE-2019-1084 is a vulnerability of currently unknown severity. An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. EPSS estimates a 5.33% chance of exploitation in the next 30 days.
Description
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Exchange Server | 2010 | Sp2 |
| Microsoft | Exchange Server | 2013 | Cumulative Update 23 |
| Microsoft | Exchange Server | 2016 | Cumulative Update 1 |
| Microsoft | Lync | 2013 | Sp1 |
| Microsoft | Lync Basic | 2013 | Sp1 |
| Microsoft | Mail And Calendar | All versions | — |
| Microsoft | Office | 2010 | Sp2 |
| Microsoft | Office | 2013 | Sp1 |
| Microsoft | Office | 2016 | — |
| Microsoft | Office | 2019 | — |
| Microsoft | Office 365 Proplus | All versions | — |
| Microsoft | Outlook | All versions | — |
| Microsoft | Outlook | 2013 | Sp1 |
| Microsoft | Outlook | 2016 | — |
| Microsoft | Skype For Business | 2016 | — |
| Microsoft | Skype For Business Basic | 2016 | — |
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1084Patch, Vendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1084Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1084?
How severe is CVE-2019-1084?
How do I fix CVE-2019-1084?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-10806vega-util prior to 1.13.1 allows manipulation of object prot…4.3
- CVE-2019-10807Blamer versions prior to 1.0.1 allows execution of arbitrary…9.8
- CVE-2019-10808utilitify prior to 1.0.3 allows modification of object prope…8.8
- CVE-2019-1081An information disclosure vulnerability exists when affected…4.2
- CVE-2019-1082An elevation of privilege vulnerability exists in Microsoft …
- CVE-2019-1083A denial of service vulnerability exists when Microsoft Comm…
- CVE-2019-10842Arbitrary code execution (via backdoor code) was discovered …
- CVE-2019-10843Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-10844nbla/logger.cpp in libnnabla.a in Sony Neural Network Librar…
- CVE-2019-10845An issue was discovered in Uniqkey Password Manager 1.14. Wh…
- CVE-2019-10846Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cros…6.1
- CVE-2019-10847Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
Are you affected by CVE-2019-1084?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
