Microsoft Exchange CVE-2017-8560 Cross-Site Scripting Vulnerability

description-logoDescription

An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests. An attacker who successfully exploited this vulnerability could perform script/content injection attacks and attempt to trick the user into disclosing sensitive information.

affected-products-logoAffected Applications

Microsoft Exchange Server 2013 Cumulative Update 16
Microsoft Exchange Server 2013 Service Pack 1
Microsoft Exchange Server 2016 Cumulative Update 5

CVE References

CVE-2017-8560