Skip to main content

Microsoft Outlook S/MIME AIA Vulnerability

Last Update Date: 13 Nov 2013 17:04 Release Date: 13 Nov 2013 3945 Views

RISK: Medium Risk

TYPE: Clients - Email Clients

TYPE: Email Clients

An information disclosure vulnerability exists when Microsoft Outlook does not properly handle the expansion of S/MIME certificate metadata. An attacker who successfully exploited this vulnerability could ascertain system information, such as the IP address and open TCP ports, from the target system and other systems that share the network with the target system.


Impact

  • Information Disclosure

System / Technologies affected

  • Microsoft Office 2007
  • Microsoft Office 2010
  • Microsoft Office 2013 and Office 2013 RT

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link