CVE-2020-1173: Input Validation
Published May 21, 2020
·Updated
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'.
Affected Software
1 affected component
Microsoft Power BI Report Server
Remediation
Event History
May 21, 2020
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-1173?
CVE-2020-1173 is rated as important because it can lead to spoofing attacks.
2
How do I fix CVE-2020-1173?
To fix CVE-2020-1173, ensure that your Microsoft Power BI Report Server is updated to the latest version that includes the security patches.
3
What components are affected by CVE-2020-1173?
CVE-2020-1173 affects Microsoft Power BI Report Server.
4
What type of vulnerability is CVE-2020-1173?
CVE-2020-1173 is a spoofing vulnerability related to content-type validation.
5
Can CVE-2020-1173 be exploited remotely?
Yes, CVE-2020-1173 can potentially be exploited remotely if an attacker uploads a malicious attachment.