CVE-2016-0028Sensitive Information Exposure in Microsoft Exchange Server 2013 Cumulative Update 11

Severity
5.5MEDIUMNVD
EPSS
21.1%
top 4.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 16
Latest updateMay 14

Description

Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, aka "Microsoft Exchange Information Disclosure Vulnerability."

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

🔴Vulnerability Details

1
GHSA
GHSA-4r6v-fffh-m6fx: Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 d2022-05-14

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Information Disclosure Vulnerability2016-06-14

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday - June 20162016-06-14
Talos
Microsoft Patch Tuesday - June 20162016-06-14