CVE-2016-3379

Description

Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attackers to inject arbitrary web script or HTML via a meeting-invitation request, aka Microsoft Exchange Elevation of Privilege Vulnerability.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
7.631

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Exchange Open Redirect Vulnerability for Exchange 2010 SP3 (KB3184728)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-21360Update Rollup 15 For Exchange 2010 SP3 (KB3184728)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234