Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability."
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Microsoft Exchange | — | Download and install Microsoft KB4036108 | Aug 10, 2023 | Sep 13, 2017 |
| Msft | — | Security Update For Exchange Server 2013 SP1 (KB4036108)Security Update For Exchange Server 2013 CU16 (KB4036108)Security Update For Exchange Server 2013 CU17 (KB4036108) | Sep 12, 2017 | Sep 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub