Vulnerability Name:

CVE-2013-3905 (CCN-88385)

Assigned:2013-11-12
Published:2013-11-12
Updated:2021-08-30
Summary:Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2013-3905

Source: CCN
Type: SA55574
Microsoft Outlook X.509 S/MIME AIA Information Disclosure Vulnerability

Source: CCN
Type: Microsoft Security Bulletin MS13-094
Vulnerability in Microsoft Outlook Could Allow Information Disclosure (2894514)

Source: CCN
Type: Microsoft Security Bulletin MS16-029
Security Update for Microsoft Office to Address Remote Code Execution (3141806)

Source: CCN
Type: Microsoft Security Bulletin MS16-042
Security Update for Microsoft Office (3148775)

Source: CCN
Type: Microsoft Security Bulletin MS16-054
Security Update for Microsoft Office (3155544)

Source: CCN
Type: Microsoft Security Bulletin MS16-070
Security Update for Office (3163610)

Source: CCN
Type: Microsoft Security Bulletin MS16-088
Security Updates for Office (3170008)

Source: CCN
Type: Microsoft Security Bulletin MS16-099
Security Update for Office (3177451)

Source: CCN
Type: Microsoft Security Bulletin MS16-107
Security Update for Microsoft Office (3185852)

Source: CCN
Type: Microsoft Security Bulletin MS16-121
Security Update for Microsoft Office (3194063)

Source: CCN
Type: Microsoft Security Bulletin MS16-133
Security Update for Microsoft Office (3199168)

Source: CCN
Type: Microsoft Security Bulletin MS16-148
Security Update for Microsoft Office (3204068)

Source: CCN
Type: Microsoft Security Bulletin MS17-002
Security Update for Microsoft Office (3214291)

Source: CCN
Type: Microsoft Security Bulletin MS17-013
Security Update for Microsoft Graphics Component (4013075)

Source: CCN
Type: Microsoft Security Bulletin MS17-014
Security Update for Microsoft Office (4013241)

Source: CCN
Type: BID-63603
Microsoft Outlook CVE-2013-3905 Information Disclosure Vulnerability

Source: CERT
Type: US Government Resource
TA13-317A

Source: MS
Type: UNKNOWN
MS13-094

Source: XF
Type: UNKNOWN
ms-outlook-cve20133905-info-disc(88385)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:19239

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:outlook:2013:-:-:*:-:-:x86:*
  • OR cpe:/a:microsoft:outlook:2010:sp2:*:*:*:x86:*:*
  • OR cpe:/a:microsoft:outlook:2010:sp1:*:*:*:x86:*:*
  • OR cpe:/a:microsoft:outlook:2010:sp1:*:*:*:*:x64:*
  • OR cpe:/a:microsoft:outlook:2010:sp2:*:*:*:*:x64:*
  • OR cpe:/a:microsoft:outlook:2007:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:outlook:2013:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:outlook:2013:-:-:*:-:-:x64:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:outlook:2007:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:outlook:2010:sp1:*:*:*:*:x64:*
  • OR cpe:/a:microsoft:outlook:2010:sp2:*:*:*:*:x32:*
  • OR cpe:/a:microsoft:outlook:2010:sp2:*:*:*:*:x64:*
  • OR cpe:/a:microsoft:outlook:2013:-:-:*:-:-:x64:*
  • OR cpe:/a:microsoft:outlook:2013:*:*:*:rt:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:19239
    V
    S/MIME AIA Vulnerability (CVE-2013-3905) - MS13-094
    2013-12-30
    BACK
    microsoft outlook 2013 -
    microsoft outlook 2010 sp2
    microsoft outlook 2010 sp1
    microsoft outlook 2010 sp1
    microsoft outlook 2010 sp2
    microsoft outlook 2007 sp3
    microsoft outlook 2013
    microsoft outlook 2013 -
    microsoft outlook 2007 sp3
    microsoft outlook 2010 sp1
    microsoft outlook 2010 sp2
    microsoft outlook 2010 sp2
    microsoft outlook 2013 -
    microsoft outlook 2013 rt -