CVE-2019-1105 - Outlook for Android Spoofing Vulnerability

    CVE-2019-1105 - Outlook for Android Spoofing Vulnerability

    CVE-2019-1105 - Outlook for Android Spoofing Vulnerability


    Posted: 20 Jun 2019

    A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim.

    The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on the affected systems and run scripts in the security context of the current user.

    The security update addresses the vulnerability by correcting how Outlook for Android parses specially crafted email messages.


    Exploitability Assessment

    The following table provides an exploitability assessment for this vulnerability at the time of original publication.

    Publicly Disclosed Exploited Latest Software Release Older Software Release Denial of Service
    No No Not Applicable Not Applicable Not Applicable

    Security Updates

    To determine the support life cycle for your software version or edition, see the Microsoft Support Lifecycle.

    Product Platform Article Download Impact Severity Supersedence
    Microsoft Outlook for Android Release Notes Security Update Spoofing Important

    Mitigations

    Microsoft has not identified any mitigating factors for this vulnerability.

    Workarounds

    Microsoft has not identified any workarounds for this vulnerability.

    FAQ

    How do I get the update for Outlook for Android?

    1. Tap the Google Play icon on your home screen.
    2. Swipe in from the left edge of the screen.
    3. Tap My apps & games.
    4. Tap the Update box next to the Outlook app.

    Acknowledgements



    See acknowledgements for more information.

    Disclaimer

    The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

    Revisions

    Version Date Description
    1.0 06/20/2019 Information published.

    Source: https://portal.msrc.microsoft.com/en.../CVE-2019-1105
    Brink's Avatar Posted By: Brink
    20 Jun 2019


  1. Posts : 800
    Windows 10 Home x64
       #1

    Updated app on my Android device appeared literally within minutes of the above post.
    One thing sadly is missing there: release notes do not contain any of the above...
    CVE-2019-1105 - Outlook for Android Spoofing Vulnerability-image.png
      My Computers


  2. Posts : 102
    Windows 10
       #2

    just checked the google play store and there's no update. It says it was updated yesterday. Could I have gotten this update before they announced it?
      My Computer


  3. Posts : 800
    Windows 10 Home x64
       #3

    Just check the version of the app installed within your phone / tablet.
      My Computers


  4. Posts : 102
    Windows 10
       #4

    krzemien said:
    Just check the version of the app installed within your phone / tablet.
    It's the same version as the one reported. Guess I got the update before they announced it lol
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 14:17.
Find Us




Windows 10 Forums