CVE-2020-16949

CWE-401Memory Leak4 documents4 sources
Severity
7.5HIGH
EPSS
6.4%
top 8.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could cause a remote denial of service against a system. Exploitation of the vulnerability requires that a specially crafted email be sent to a vulnerable Outlook server. The security update addresses the vulnerability by correcting how Microsoft Outlook handles objects in memory.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages9 packages

CVEListV5microsoft/microsoft_outlook_2010_service_pack_213.0.0.0publication
CVEListV5microsoft/microsoft_outlook_2013_service_pack_115.0.0.0publication
CVEListV5microsoft/microsoft_outlook_201616.0.0.0publication
NVDmicrosoft/outlook2010, 2013, 2016+2
CVEListV5microsoft/microsoft_office_201919.0.0https://aka.ms/OfficeSecurityReleases

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cvmr-qp3p-228w: A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory, aka 'Microsoft Ou2022-05-24
CVEList
Microsoft Outlook Denial of Service Vulnerability2020-10-16

📋Vendor Advisories

1
Microsoft
Microsoft Outlook Denial of Service Vulnerability2020-10-13