CVE-2020-1493: Microsoft Outlook Information Disclosure Vulnerability
An information disclosure vulnerability exists when attaching files to Outlook messages, aka 'Microsoft Outlook Information Disclosure Vulnerability'.
Other sources
An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users. To exploit this vulnerability, an attacker would have to attach a file as a link to an email. The email could then be shared with individuals that should not have access to the files, ignoring the default organizational setting. The security update addresses the vulnerability by correcting how Outlook handles file attachment links.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-1493?
CVE-2020-1493 is an information disclosure vulnerability that exists when attaching files to Outlook messages.
What is the severity of CVE-2020-1493?
The severity of CVE-2020-1493 is medium, with a severity value of 5.5.
Which software versions are affected by CVE-2020-1493?
Microsoft Office LTSC for Mac 2021, Microsoft Office 2019, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 are affected by CVE-2020-1493.
How can I fix CVE-2020-1493?
Apply the security updates provided by Microsoft to fix CVE-2020-1493.
Where can I find more information about CVE-2020-1493?
You can find more information about CVE-2020-1493 on the Microsoft Security Guidance Advisory and Packet Storm Security websites.