CVE-2013-3905: Infoleak
Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3905?
CVE-2013-3905 is categorized as a medium severity vulnerability due to its potential for misuse by remote attackers.
How do I fix CVE-2013-3905?
To resolve CVE-2013-3905, install the latest security updates provided by Microsoft for affected versions of Outlook.
Which versions of Outlook are affected by CVE-2013-3905?
CVE-2013-3905 affects Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT.
What types of attacks can exploit CVE-2013-3905?
CVE-2013-3905 can be exploited through a crafted S/MIME certificate included in an e-mail message, which may expose sensitive information.
Is CVE-2013-3905 related to S/MIME certificates?
Yes, CVE-2013-3905 specifically concerns the improper expansion of metadata in S/MIME certificates used in Outlook.