ADV190014 | Microsoft Live Accounts Elevation of Privilege Vulnerability

Security Advisory
Published: 08/13/2019

An elevation of privilege vulnerability exists in Outlook Web Access (OWA) regarding a possible unsigned token. An attacker who successfully exploited this vulnerability could have access to another person's email inbox.

To exploit this vulnerability, an attacker would first have to replace an unsigned token with a different one.

This vulnerability has been mitigated for all users' Microsoft Live accounts.

Security Updates

To determine the support life cycle for your software version or edition, see the Microsoft Support Lifecycle.

Product Platform Article Download Impact Severity Supersedence
Microsoft Exchange Online Elevation of Privilege Important
Microsoft Office 365 Elevation of Privilege Important
Outlook.com Elevation of Privilege Important

Mitigations

Microsoft has not identified any mitigating factors for this vulnerability.

Workarounds

Microsoft has not identified any workarounds for this vulnerability.

FAQ

Does my network administrator need to do anything to protect me from this attack?
No, Microsoft has mitigated the attack vector to protect online mailboxes from this vulnerability. No further action is required.

Acknowledgements


See acknowledgements for more information.

Disclaimer

The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

Revisions

Version Date Description
1.0 08/13/2019 Information published.

Source: https://portal.msrc.microsoft.com/en...sory/ADV190014