Intrusion Prevention

MS.Office.RTF.Email.OLE.Information.Disclosure

Description

This indicates an attack attempt to exploit an Information Disclosure Vulnerability in Microsoft Outlook email client.
The vulnerability is due to an error when the vulnerable software handles a maliciously crafted RTF based email. A remote attacker could exploit this to disclose sensitive information within the context of the application, via a crafted email.

Affected Products

Microsoft Outlook

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0950

CVE References

CVE-2018-0950