CVE-2024-43482: Microsoft Outlook for iOS Information Disclosure Vulnerability

Overview

Severity
Medium (CVSS 6.5)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2024-Sep
Released
2024-09-10
EPSS Score
5.86% (percentile: 90.6%)

FAQ

How do I get the update for Outlook for IOS? Tap the Settings Icon Tap the iTunes & App Store Turn on AUTOMATIC DOWNLOADS for Apps Alternatively Tap the App Store Icon Scroll down to find Microsoft Outlook Tap the Update button What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is file content.

Affected Products (1)

Microsoft Office

  • Outlook for iOS

Security Updates (1)

Acknowledgments

Masahiro Iida with <a href="https://www.lac.co.jp/">LAC Co., Ltd.</a>

Revision History

  • 2024-09-10: Information published.