CVE-2020-1229
published 2020-06-09CVE-2020-1229: A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft…
PriorityP424medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
3.84%
89.0th percentile
A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| microsoft | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| microsoft | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_office | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | microsoft_word | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc4.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2023-1228
vendor_chrome·2023-03-07·CVSS 4.3
CVE-2023-1228 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-1228
Stable Channel Update for Desktop
CVE-2023-1228: Insufficient policy enforcement in Intents. Reported by Axel Chong on 2022-09-18 [$2000][ 1160485 ] Medium CVE-2023-1229: Inappropriate implementation in Permission prompts
Reported by Thomas Orlita on 2020-12-20 [$2000][ 1404230 ] Medium CVE-2023-1230: Inappropriate implementation in WebApp Installs
Severity: medium
Microsoft
Microsoft Outlook Security Feature Bypass Vulnerability
vendor_msrc·2020-06-09·CVSS 4.3
CVE-2020-1229 [MEDIUM] Microsoft Outlook Security Feature Bypass Vulnerability
Microsoft Outlook Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system. An attacker who successfully exploited this vulnerability could cause a system to load remote images. These images could disclose the IP address of the targeted system to the attacker.
Exploitation of the vulnerability requires that a user open a specially crafted image with an affected version of Microsoft Office software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted image to the user.
The update addresses the vulnerability by changing how remote images are processed in Outlook.
FAQ: Is the Preview Pane an attack vector fo
GHSA
GHSA-gmw9-2jwr-g5m7: A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Micros
ghsa_unreviewed·2022-05-24
CVE-2020-1229 [MEDIUM] CWE-200 GHSA-gmw9-2jwr-g5m7: A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Micros
A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
No detection rules found.
No public exploits indexed.
Krebs
Microsoft Patch Tuesday, June 2020 Edition
blogs_krebs·2020-06-15·CVSS 10.0
[CRITICAL] Microsoft Patch Tuesday, June 2020 Edition
Microsoft today released software patches to plug at least 129 security holes in its Windows operating systems and supported software, by some accounts a record number of fixes in one go for the software giant. None of the bugs addressed this month are known to have been exploited or detailed prior to today, but there are a few vulnerabilities that deserve special attention — particularly for enterprises and employees working remotely.
A chief concern among the panoply of patches is a trio of vulnerabilities in the Windows file-sharing technology (a.k.a. Microsoft Server Message Block or “SMB” service). Perhaps most troubling of these (CVE-2020-1301) is a remote code execution bug in SMB capabilities built into Windows 7 and Windows Server 2008 systems — both operating systems that Micros
Krebs
Microsoft Patch Tuesday, June 2020 Edition
blogs_krebs·2020-06-10·CVSS 10.0
[CRITICAL] Microsoft Patch Tuesday, June 2020 Edition
Microsoft today released software patches to plug at least 129 security holes in its Windows operating systems and supported software, by some accounts a record number of fixes in one go for the software giant. None of the bugs addressed this month are known to have been exploited or detailed prior to today, but there are a few vulnerabilities that deserve special attention — particularly for enterprises and employees working remotely.
June marks the fourth month in a row that Microsoft has issued fixes to address more than 100 security flaws in its products. Eleven of the updates address problems Microsoft deems “critical,” meaning they could be exploited by malware or malcontents to seize complete, remote control over vulnerable systems without any help from users.
A chief concern amon
Trendmicro
Patch Tuesday: Fixes for LNK, SMB, and SharePoint Bugs
blogs_trendmicro·2020-06-10·CVSS 8.8
[HIGH] Patch Tuesday: Fixes for LNK, SMB, and SharePoint Bugs
Exploits & Vulnerabilities
# Patch Tuesday: Fixes for LNK, SMB, and SharePoint Bugs
This month’s Patch Tuesday had the highest number of entries so far in 2020 — a whopping 129, a continuation of the trend seen from the previous months. The update includes fixes for LNK, SMB, SharePoint, and Win32k vulnerabilities.
By: Trend Micro
2020/06/10
Read time: ( words)
Save to Folio
This month’s Patch Tuesday had the highest number of entries so far in 2020 — a whopping 129, a continuation of the trend seen from the previous months. The update includes fixes for LNK, SMB, SharePoint, and Win32k vulnerabilities.
While the update contained a significant number of patches, only 11 were rated Critical. One of the patches addresses yet another LNK-related vulnerability, CVE-2020-1299, which atta
2020-06-09
Published