cbcvebase.
CVE-2017-11761
published 2017-09-13

CVE-2017-11761: Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in…

PriorityP430medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
6.56%
93.1th percentile
Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability"

Affected

7 ranges
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoft_corporationmicrosoft_exchange_server
msrcmicrosoft_exchange_server_2013_cumulative_update_17
msrcmicrosoft_exchange_server_2013_cumulative_update_18
msrcmicrosoft_exchange_server_2016_cumulative_update_6
msrcmicrosoft_exchange_server_2016_cumulative_update_7

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc5.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.