CVE-2019-1460 describes a spoofing vulnerability in Microsoft Outlook for Android, stemming from how the application parses specially crafted email messages. This medium-severity vulnerability (CVSS 4.6) requires user interaction (UI:R) and low privileges (PR:L) for a successful attack, potentially leading to limited confidentiality and integrity impacts (C:L/I:L). While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:outlook:-:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.