PT-2018-9162 · Microsoft · Exchange Server 2016+4

Llt4L

·

Publicado

2018-03-13

·

Atualizado

2020-08-24

·

CVE-2018-0940

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Exchange Server 2010 version 14.3.452.0 (Service Pack 3 Update Rollup 20) Microsoft Exchange Server 2013 versions 15.0.1497.2 through 15.0.1514.2 Microsoft Exchange Server 2016 versions 15.1.1034.26 through 15.1.1066.14
Description: The issue arises from how links in the body of an email message are rewritten, allowing an elevation of privilege. This occurs because Microsoft Exchange Outlook Web Access (OWA) fails to properly sanitize links presented to users. An attacker could exploit this to override the OWA interface with a fake login page, attempting to trick the user into disclosing sensitive information.
Recommendations: For Microsoft Exchange Server 2010 version 14.3.452.0, update to a version that includes the fix for this issue. For Microsoft Exchange Server 2013 versions 15.0.1497.2 through 15.0.1514.2, update to a version that includes the fix for this issue. For Microsoft Exchange Server 2016 versions 15.1.1034.26 through 15.1.1066.14, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to links in email messages to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-0940

Produtos afetados

Exchange Server
Exchange Outlook Web Access
Exchange Server 2010
Exchange Server 2013
Exchange Server 2016