CVE-2020-1432
published 2020-07-14CVE-2020-1432: An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer…
PriorityP421medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
4.45%
90.4th percentile
An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11_on_windows_10_version_1903_for_32-bit_systems | — | — |
| microsoft | internet_explorer_11_on_windows_10_version_1903_for_arm64-based_systems | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-775r-4pcv-6q97: An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explore
ghsa_unreviewed·2022-05-24
CVE-2020-1432 [MEDIUM] CWE-200 GHSA-775r-4pcv-6q97: An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explore
An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'.
Microsoft
Skype for Business via Internet Explorer Information Disclosure Vulnerability
vendor_msrc·2020-07-14·CVSS 4.3
CVE-2020-1432 [MEDIUM] Skype for Business via Internet Explorer Information Disclosure Vulnerability
Skype for Business via Internet Explorer Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer. An attacker who exploited the vulnerability could cause the user to place a call without additional consent, leading to information disclosure of the user profile.
For the vulnerability to be exploited, a user must click a specially crafted URL that prompts the Skype app. In an email attack scenario, an attacker could exploit the vulnerability by sending an email message containing the specially crafted URL to the user and convincing the user to click the specially crafted URL.
The security update addresses the vulnerability by correcting how Internet Explorer handles URLs that are designed to u
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-07-14
Published