Beschreibung
Multiple serious vulnerabilities have been found in Microsoft Exchange Server. Malicious users can exploit these vulnerabilities to obtain sensitive information and gain privileges.
Below is a complete list of vulnerabilities:
- An information disclosure vulnerability in way that Microsoft Exchange Server handles URL redirects can be exploited via link in an email by attacker to obtain sensitive information;
- An elevation of privilege vulnerability in Microsoft Exchange Outlook Web Access (OWA) can be exploited via specially crafted email message containing a malicious link to gain priveleges;
- An elevation of privilege vulnerability in the way that Microsoft Exchange Server handles importing data can be exploited via specially crafted file to obtain sensitive information.
Ursprüngliche Informationshinweise
CVE Liste
- CVE-2018-0924 warning
- CVE-2018-0940 warning
- CVE-2018-0941 warning
KB Liste
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com
Sie haben einen Fehler in der Beschreibung der Schwachstelle gefunden? Mitteilen!