PT-2017-18410 · Microsoft · Exchange Outlook Web Access+1

Publicado

2017-07-11

·

Atualizado

2017-07-14

·

CVE-2017-8559

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server versions 2010 SP3, 2013 SP3, 2013 CU16, and 2016 CU5
Description An elevation of privilege issue exists due to the way Microsoft Exchange Outlook Web Access (OWA) handles web requests. This could allow an attacker to perform script or content injection attacks, potentially tricking users into disclosing sensitive information. Exploitation requires a user to click on a maliciously crafted link.
Recommendations For Microsoft Exchange Server 2010 SP3, update to a version that includes the fix for this issue. For Microsoft Exchange Server 2013 SP3, update to a version that includes the fix for this issue. For Microsoft Exchange Server 2013 CU16, update to a version that includes the fix for this issue. For Microsoft Exchange Server 2016 CU5, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to OWA to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-8559

Produtos afetados

Exchange Server
Exchange Outlook Web Access