CVE-2017-11932

Description

Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka Microsoft Exchange Spoofing Vulnerability.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
14.796

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Exchange Information Disclosure Vulnerability for Exchange Server 2013 CU18 (KB4045655)Windows
Microsoft Exchange Information Disclosure Vulnerability for Exchange Server 2013 CU17 (KB4045655)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-23599Security Update For Exchange Server 2013 CU18 (KB4045655)
PATCH-23600Security Update For Exchange Server 2013 CU17 (KB4045655)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234