vendor:
Microsoft People
by:
L0RD
7.5
CVSS
HIGH
Denial of Service
N/A
CWE
Product Name: Microsoft People
Affected Version From: 10.1807.2131.0
Affected Version To: 10.1807.2131.0
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:people
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2018
Microsoft people 10.1807.2131.0 – Denial of Service (PoC)
Microsoft people desktop application is a contact management app and address book included in Microsoft's Windows 8 and 10. It allows a user to organize and link contacts from different email accounts with a unique graphical interface. An attacker can create a malicious file containing a large number of characters and paste it into the name field of the application, causing the application to crash.
Mitigation:
Ensure that the application is updated to the latest version and that all security patches are applied.