CVE-2019-1084

Description

An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka Microsoft Exchange Information Disclosure Vulnerability.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
9.029

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Exchange Information Disclosure Vulnerability For Exchange Server 2013 CU23 (KB4509409)Windows
Microsoft Exchange Information Disclosure Vulnerability For Exchange Server 2016 CU12 (KB4509409)Windows
Microsoft Exchange Information Disclosure Vulnerability For Exchange Server 2016 CU13 (KB4509409)Windows
Microsoft Exchange Information Disclosure Vulnerability For Exchange 2010 SP3 (KB4509410)Windows
Microsoft Exchange Information Disclosure Vulnerability for Skype for Business 2016 (KB4475545) 32-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Skype for Business 2016 (KB4475545) 64-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability For Exchange Server 2019 CU2 (KB4509408)Windows
Microsoft Exchange Information Disclosure Vulnerability For Exchange Server 2019 CU1 (KB4509408)Windows
Microsoft Exchange Information Disclosure Vulnerability for Microsoft Office 2013 (KB4464558) 64-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Microsoft Office 2013 (KB4464558) 32-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Skype for Business 2015 (KB4475519) 64-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Skype for Business 2015 (KB4475519) 32-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Microsoft Outlook 2010 (KB4475509) 64-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Microsoft Outlook 2010 (KB4475509) 32-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Microsoft Outlook 2016 (KB4475517) 64-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Microsoft Outlook 2016 (KB4475517) 32-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Microsoft Outlook 2013 (KB4464592) 32-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Microsoft Outlook 2013 (KB4464592) 64-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Microsoft Office 2016 (KB4475514) 32-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Microsoft Office 2016 (KB4475514) 64-Bit EditionWindows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Professional Plus Semi-Annual Channel for x86 Version 1808 (Build 10730.20360)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Professional Plus Semi-Annual Channel for x64 Version 1808 (Build 10730.20360)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Business Edition Semi-Annual Channel for x86 Version 1808 (Build 10730.20360)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Business Edition Semi-Annual Channel for x64 Version 1808 (Build 10730.20360)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Semi-Annual Channel Version 1808 (Build 10730.20360)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Professional Plus Targeted Channel for x86 Version 1902 (Build 11328.20368)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Professional Plus Targeted Channel for x64 Version 1902 (Build 11328.20368)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Targeted Channel Version 1902 (Build 11328.20368)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Professional Plus Monthly Channel for x86 Version 1906 (Build 11727.20244)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Professional Plus Monthly Channel for x64 Version 1906 (Build 11727.20244)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Business Edition Monthly Channel for x86 Version 1906 (Build 11727.20244)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Business Edition Monthly Channel for x64 Version 1906 (Build 11727.20244)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Monthly Channel Version 1906 (Build 11727.20244)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Professional Plus Semi-Annual Channel for x86 Version 1808 (Build 10730.20360)Windows
Microsoft Exchange Information Disclosure Vulnerability for Office 365 Business Edition Semi-Annual Channel for x64 Version 1808 (Build 10730.20360)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-27157Security Update For Exchange Server 2013 CU23 (KB4509409)
PATCH-27158Security Update For Exchange Server 2016 CU12 (KB4509409)
PATCH-27159Security Update For Exchange Server 2016 CU13 (KB4509409)
PATCH-27156Security Update Rollup 29 For Exchange 2010 SP3 (KB4509410)
PATCH-27127Security Update for Skype for Business 2016 (KB4475545) 32-Bit Edition
PATCH-27128Security Update for Skype for Business 2016 (KB4475545) 64-Bit Edition
PATCH-27160Security Update For Exchange Server 2019 CU2 (KB4509408)
PATCH-27161Security Update For Exchange Server 2019 CU1 (KB4509408)
PATCH-27111Security Update for Microsoft Office 2013 (KB4464558) 64-Bit Edition
PATCH-27112Security Update for Microsoft Office 2013 (KB4464558) 32-Bit Edition
PATCH-27113Security Update for Skype for Business 2015 (KB4475519) 64-Bit Edition
PATCH-27114Security Update for Skype for Business 2015 (KB4475519) 32-Bit Edition
PATCH-27101Security Update for Microsoft Outlook 2010 (KB4475509) 64-Bit Edition
PATCH-27102Security Update for Microsoft Outlook 2010 (KB4475509) 32-Bit Edition
PATCH-27125Security Update for Microsoft Outlook 2016 (KB4475517) 64-Bit Edition
PATCH-27126Security Update for Microsoft Outlook 2016 (KB4475517) 32-Bit Edition
PATCH-27115Security Update for Microsoft Outlook 2013 (KB4464592) 32-Bit Edition
PATCH-27116Security Update for Microsoft Outlook 2013 (KB4464592) 64-Bit Edition
PATCH-27123Security Update for Microsoft Office 2016 (KB4475514) 32-Bit Edition
PATCH-27124Security Update for Microsoft Office 2016 (KB4475514) 64-Bit Edition
PATCH-27148Update for Office 365 Professional Plus Semi-Annual Channel for x64 Version 1808 (Build 10730.20360)
PATCH-27150Update for Office 365 Business Edition Semi-Annual Channel for x86 Version 1808 (Build 10730.20360)
PATCH-27155Update for Office 365 Semi-Annual Channel Version 1808 (Build 10730.20360)
PATCH-27138Update for Office 365 Professional Plus Targeted Channel for x86 Version 1902 (Build 11328.20368)
PATCH-27140Update for Office 365 Professional Plus Targeted Channel for x64 Version 1902 (Build 11328.20368)
PATCH-27154Update for Office 365 Targeted Channel Version 1902 (Build 11328.20368)
PATCH-27130Update for Office 365 Professional Plus Monthly Channel for x86 Version 1906 (Build 11727.20244)
PATCH-27132Update for Office 365 Professional Plus Monthly Channel for x64 Version 1906 (Build 11727.20244)
PATCH-27134Update for Office 365 Business Edition Monthly Channel for x86 Version 1906 (Build 11727.20244)
PATCH-27136Update for Office 365 Business Edition Monthly Channel for x64 Version 1906 (Build 11727.20244)
PATCH-27153Update for Office 365 Monthly Channel Version 1906 (Build 11727.20244)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234