A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim.
The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on the affected systems and run scripts in the security context of the current user.
The security update addresses the vulnerability by correcting how Outlook for Android parses specially crafted email messages.
Exploitability Assessment
The following table provides an exploitability assessment for this vulnerability at the time of original publication.
Publicly Disclosed |
Exploited |
Latest Software Release |
Older Software Release |
Denial of Service |
No |
No |
Not Applicable |
Not Applicable |
Not Applicable |
Security Updates
To determine the support life cycle for your software version or edition, see the
Microsoft Support Lifecycle.
Product |
Platform |
Article |
Download |
Impact |
Severity |
Supersedence |
Microsoft Outlook for Android |
|
Release Notes |
Security Update |
Spoofing |
Important |
|
Mitigations
Microsoft has not identified any
mitigating factors for this vulnerability.
Workarounds
Microsoft has not identified any
workarounds for this vulnerability.
FAQ
How do I get the update for Outlook for Android?
- Tap the Google Play icon on your home screen.
- Swipe in from the left edge of the screen.
- Tap My apps & games.
- Tap the Update box next to the Outlook app.
Acknowledgements
See
acknowledgements for more information.
Disclaimer
The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.
Revisions
Version |
Date |
Description |
1.0 |
06/20/2019 |
Information published. |