First published: Fri Oct 16 2020(Updated: )
<p>A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could cause a remote denial of service against a system.</p> <p>Exploitation of the vulnerability requires that a specially crafted email be sent to a vulnerable Outlook server.</p> <p>The security update addresses the vulnerability by correcting how Microsoft Outlook handles objects in memory.</p>
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1903 | |
Microsoft Windows 10 | =1909 | |
Microsoft Windows 10 | =2004 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT 8.1 | ||
Microsoft Windows Server 2008 | =sp2 | |
Microsoft Windows Server 2008 | =r2-sp1 | |
Microsoft Windows Server 2012 | ||
Microsoft Windows Server 2012 | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =1903 | |
Microsoft Windows Server 2016 | =1909 | |
Microsoft Windows Server 2016 | =2004 | |
Microsoft Windows Server 2019 | ||
Microsoft 365 Apps | ||
Microsoft Office | =2019 | |
Microsoft Outlook | =2010-sp2 | |
Microsoft Outlook | =2013-sp1 | |
Microsoft Outlook | =2013-sp1 | |
Microsoft Outlook | =2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16949 is a denial of service vulnerability in Microsoft Outlook software.
CVE-2020-16949 causes Microsoft Outlook to fail when handling objects in memory.
CVE-2020-16949 affects Microsoft Windows 7, Windows 8.1, Windows 10, Windows Server 2008, Windows Server 2012, Windows Server 2016, Windows Server 2019, Microsoft Office 2019, Microsoft Office LTSC for Mac 2021, and specific versions of Microsoft Outlook (2010, 2013, 2016).
CVE-2020-16949 has a severity rating of 7.5 (high).
To fix CVE-2020-16949, apply the security update provided by Microsoft, as mentioned in the reference link.