CVE-2016-3378

Description

Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Microsoft Exchange Open Redirect Vulnerability.

Risk Information

Base Score
7.4
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
EPSS Score
Exploitation Probability
3.118

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Exchange Open Redirect Vulnerability for Exchange 2010 SP3 (KB3184728)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-21360Update Rollup 15 For Exchange 2010 SP3 (KB3184728)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234