PT-2015-2775 · Microsoft · Exchange Server Cumulative Update 8+2

Published

2015-06-09

·

Updated

2018-10-12

·

CVE-2015-1771

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server 2013 SP1 Microsoft Exchange Server Cumulative Update 8
Description The issue is related to a cross-site request forgery (CSRF) vulnerability in the web applications of Microsoft Exchange Server. This vulnerability allows remote attackers to hijack the authentication of arbitrary users. The exploitation of this vulnerability requires the victim to be authenticated to the target site, and it is related to the improper management of user sessions by Exchange.
Recommendations For Microsoft Exchange Server 2013 SP1, update to a version that properly manages user sessions to prevent CSRF attacks. For Microsoft Exchange Server Cumulative Update 8, ensure that user sessions are correctly handled to mitigate the risk of elevation of privilege attacks. As a temporary workaround, consider implementing additional authentication measures to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-12140
CVE-2015-1771

Affected Products

Exchange Server
Exchange Server 2013 Sp1
Exchange Server Cumulative Update 8