CVE-2017-0110
published 2017-03-17CVE-2017-0110: Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrary web script or HTML via a…
PriorityP431medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
7.02%
93.5th percentile
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrary web script or HTML via a crafted email or chat client, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft_corporation | exchange_server | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_14 | — | — |
| msrc | microsoft_exchange_server_2013_service_pack_1 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_3 | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_msrc6.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-54rc-hfr6-cj3x: Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrary web script or HTML
ghsa_unreviewed·2022-05-14
CVE-2017-0110 [MEDIUM] CWE-79 GHSA-54rc-hfr6-cj3x: Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrary web script or HTML
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrary web script or HTML via a crafted email or chat client, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability."
Microsoft
Microsoft Exchange Server Elevation of Privilege Vulnerability
vendor_msrc·2017-03-14·CVSS 6.1
CVE-2017-0110 [MEDIUM] Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests. An attacker who successfully exploited this vulnerability could perform script/content injection attacks and attempt to trick the user into disclosing sensitive information.
To exploit the vulnerability, an attacker could send a specially crafted email message containing a malicious link to a user. Alternatively, an attacker could use a chat client to social engineer a user into clicking the malicious link.
The security update addresses the vulnerability by correcting how Microsoft Exchange validates web requests.
Note: In order to exploit this vulnerability, a user must click a ma
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/96621http://www.securitytracker.com/id/1038011https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0110http://www.securityfocus.com/bid/96621http://www.securitytracker.com/id/1038011https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0110
2017-03-17
Published