PT-2018-2092 · Microsoft · Exchange Server

Adrian Ivascu

·

Published

2018-10-09

·

Updated

2019-10-03

·

CVE-2018-8448

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server (affected versions not specified)
Description The issue is related to insufficient access restrictions in the Exchange Outlook Web Access (OWA) component of Microsoft Exchange Server. It can be exploited by a remote attacker who sends a specially crafted email with a malicious link to a user, potentially leading to the disclosure of protected information. The vulnerability can also be used to perform script or content injection attacks, attempting to trick the user into revealing sensitive information. This requires the user to click on a maliciously crafted link sent by the attacker.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00043
CVE-2018-8448

Affected Products

Exchange Server