PT-2018-13753 · Microsoft · Exchange Server

Alphan Yavas

·

Published

2018-09-21

·

Updated

2018-11-20

·

CVE-2018-16793

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server versions prior to Rollup 18 for Microsoft Exchange Server 2010 SP3
Description The issue concerns a Server-Side Request Forgery (SSRF) vulnerability. It can be exploited via the username parameter in the "/owa/auth/logon.aspx" API endpoint, which is part of the OWA (Outlook Web Access) login page.
Recommendations For versions prior to Rollup 18 for Microsoft Exchange Server 2010 SP3, apply Rollup 18 to resolve the issue. As a temporary workaround, consider restricting access to the "/owa/auth/logon.aspx" API endpoint to minimize the risk of exploitation. Avoid using the username parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16793

Affected Products

Exchange Server