Lucene search

K
cve[email protected]CVE-2019-0588
HistoryJan 08, 2019 - 9:29 p.m.

CVE-2019-0588

2019-01-0821:29:02
CWE-732
web.nvd.nist.gov
57
cve
2019
0588
information disclosure
microsoft exchange
powershell
api
calendar contributors
nvd
vulnerability

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

49.2%

An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka “Microsoft Exchange Information Disclosure Vulnerability.” This affects Microsoft Exchange Server.

Affected configurations

Vulners
NVD
Node
microsoftexchange_server
OR
microsoftexchange_server
OR
microsoftexchange_server
OR
microsoftexchange_server
OR
microsoftexchange_server
VendorProductVersionCPE
microsoftexchange_server*cpe:2.3:a:microsoft:exchange_server:*:*:*:*:*:*:*:*
microsoftexchange_server*cpe:2.3:a:microsoft:exchange_server:*:*:*:*:*:*:*:*
microsoftexchange_server*cpe:2.3:a:microsoft:exchange_server:*:*:*:*:*:*:*:*
microsoftexchange_server*cpe:2.3:a:microsoft:exchange_server:*:*:*:*:*:*:*:*
microsoftexchange_server*cpe:2.3:a:microsoft:exchange_server:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Microsoft Exchange Server",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "2010 Service Pack 3 Update Rollup 25"
      },
      {
        "status": "affected",
        "version": "2013 Cumulative Update 21"
      },
      {
        "status": "affected",
        "version": "2016 Cumulative Update 10"
      },
      {
        "status": "affected",
        "version": "2016 Cumulative Update 11"
      },
      {
        "status": "affected",
        "version": "2019"
      }
    ]
  }
]

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

49.2%