Microsoft Outlook S/MIME AIA Vulnerability
Last Update Date:
13 Nov 2013 17:04
Release Date:
13 Nov 2013
3945
Views
RISK: Medium Risk
TYPE: Clients - Email Clients
An information disclosure vulnerability exists when Microsoft Outlook does not properly handle the expansion of S/MIME certificate metadata. An attacker who successfully exploited this vulnerability could ascertain system information, such as the IP address and open TCP ports, from the target system and other systems that share the network with the target system.
Impact
- Information Disclosure
System / Technologies affected
- Microsoft Office 2007
- Microsoft Office 2010
- Microsoft Office 2013 and Office 2013 RT
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/ms13-094
Vulnerability Identifier
Source
Related Link
Share with