CVE-2017-11761
published 2017-09-13CVE-2017-11761: Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in…
PriorityP430medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
6.56%
93.1th percentile
Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability"
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft_corporation | microsoft_exchange_server | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_17 | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_18 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_6 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_7 | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc5.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pf3p-qjm3-w7j2: Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially res
ghsa_unreviewed·2022-05-17
CVE-2017-11761 [MEDIUM] CWE-200 GHSA-pf3p-qjm3-w7j2: Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially res
Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability"
Microsoft
Microsoft Exchange Information Disclosure Vulnerability
vendor_msrc·2017-09-12·CVSS 5.3
CVE-2017-11761 [MEDIUM] Microsoft Exchange Information Disclosure Vulnerability
Microsoft Exchange Information Disclosure Vulnerability
Description: An input sanitization issue exists with Microsoft Exchange that could potentially result in unintended Information Disclosure. An attacker who successfully exploited the vulnerability could identify the existence of RFC1918 addresses on the local network from a client on the Internet. An attacker could use this internal host information as part of a larger attack.
To exploit the vulnerability, an attacker could include specially crafted tags in Calendar-related messages sent to an Exchange server. These specially-tagged messages could prompt the Exchange server to fetch information from internal servers. By observing telemetry from these requests, a client could discern properties of internal hosts intended to be hidden
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/100731http://www.securitytracker.com/id/1039320https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11761http://www.securityfocus.com/bid/100731http://www.securitytracker.com/id/1039320https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11761
2017-09-13
Published