CVE-2016-0028

Description

Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, aka Microsoft Exchange Information Disclosure Vulnerability.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
21.122

Associated Vulnerability

VulnerabilityOS Platform
Oracle Outside in Libraries Elevation of Privilege Vulnerabilities for Exchange Server 2013 CU11 (KB3150501)Windows
Oracle Outside in Libraries Elevation of Privilege Vulnerabilities for Exchange Server 2013 CU12 (KB3150501)Windows
Oracle Outside in Libraries Elevation of Privilege Vulnerabilities for Exchange Server 2013 SP1 (KB3150501)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-21016Security Update For Exchange Server 2013 CU11 (KB3150501)
PATCH-21017Security Update For Exchange Server 2013 CU12 (KB3150501)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234