First published: Tue Jan 08 2019(Updated: )
An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange Information Disclosure Vulnerability." This affects Microsoft Exchange Server.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2010-sp3_rollup25 | |
Microsoft Exchange Server | =2013-cumulative_update_21 | |
Microsoft Exchange Server | =2016-cumulative_update_10 | |
Microsoft Exchange Server | =2016-cumulative_update_11 | |
Microsoft Exchange Server | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0588 is classified as a medium severity vulnerability affecting Microsoft Exchange.
To fix CVE-2019-0588, apply the recommended security updates provided by Microsoft for your specific version of Exchange Server.
CVE-2019-0588 affects Microsoft Exchange Server 2010, 2013, 2016, and 2019 with specific updates.
CVE-2019-0588 is an information disclosure vulnerability related to excessive permissions in the PowerShell API.
Yes, CVE-2019-0588 may allow unauthorized users to gain more view permissions than intended for calendar data.