Important 2019-08 archive

Executive Summary

An elevation of privilege vulnerability exists in Outlook Web Access (OWA) regarding a possible unsigned token. An attacker who successfully exploited this vulnerability could have access to another person's email inbox. To exploit this vulnerability, an attacker would first have to replace an unsigned token with a different one. This vulnerability has been mitigated for all users' Microsoft Live accounts.

Overview

Important
MS Severity
Not Exploited
MS Exploit Status
Not Found
MS Exploit Likelihood
Category Elevation of Privilege
Released Aug 13 2019
Last Updated Aug 13 2019
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known

EPSS Score

No EPSS score available for this CVE.

View on FIRST.org

Affected Products

3 affected products
Product KB Article Severity Impact Restart Required
Microsoft Exchange Online Important Elevation of Privilege Unknown
Microsoft Office 365 Important Elevation of Privilege Unknown
Outlook.com Important Elevation of Privilege Unknown

Patches

1 patch
Article Type Restart
Unknown

Known Exploits

Acknowledgments