CVE-2020-1462
published 2020-07-14CVE-2020-1462: An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft…
PriorityP422medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
4.22%
89.8th percentile
An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_edge_on_windows_10_version_1607_for_32-bit_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1607_for_x64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1709_for_32-bit_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1709_for_arm64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1709_for_x64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1803_for_32-bit_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1803_for_arm64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1803_for_x64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1809_for_32-bit_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1809_for_arm64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1809_for_x64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1903_for_32-bit_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1903_for_arm64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1903_for_x64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1909_for_32-bit_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1909_for_arm64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_1909_for_x64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_2004_for_32-bit_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_2004_for_arm64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_10_version_2004_for_x64-based_systems | — | — |
| microsoft | microsoft_edge_on_windows_server_2016 | — | — |
| microsoft | microsoft_edge_on_windows_server_2019 | — | — |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability
vendor_msrc·2020-07-14·CVSS 4.3
CVE-2020-1462 [MEDIUM] Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability
Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based). An attacker who exploited the vulnerability could cause the user to place a call without additional consent, leading to information disclosure of the user profile.
For the vulnerability to be exploited, a user must click a specially crafted URL that prompts the Skype app. In an email attack scenario, an attacker could exploit the vulnerability by sending an email message containing the specially crafted URL to the user and convincing the user to click the specially crafted URL.
The security update addresses the vulnerability by correcting how Microsoft Edge (EdgeHTML-
GHSA
GHSA-9w6w-9279-x57j: An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Mi
ghsa_unreviewed·2022-05-24
CVE-2020-1462 [MEDIUM] CWE-200 GHSA-9w6w-9279-x57j: An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Mi
An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-07-14
Published