Описание
Multiple serious vulnerabilities have been found in Microsoft Exchange Server. Malicious users can exploit these vulnerabilities to spoof user interface. obtain sensitive information or gain privileges.
Below is a complete list of vulnerabilities
- An improper email messages parsing can be exploited remotely via a specially designed email to obtain sensitive information;
- An improper open redirect handling can be exploited remotely via a specially designed URL to spoof user interface;
- An improper meeting invitation handling can be exploited remotely via a specially designed Outlook meeting to gain privileges.
Первичный источник обнаружения
Связанные продукты
Список CVE
- CVE-2016-0138 warning
- CVE-2016-3379 warning
- CVE-2016-3378 high
Список KB
Смотрите также
Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com
Нашли неточность в описании этой уязвимости? Дайте нам знать!