CVE-2017-8758Cross-site Scripting in Corporation Microsoft Exchange Server 2016

Severity
6.1MEDIUMNVD
EPSS
0.8%
top 26.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 13
Latest updateMay 13

Description

Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability."

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5microsoft_corporation/microsoft_exchange_server_2016Microsoft Exchange Server 2016 Cumulative Update 6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5jxp-8hjc-v25c: Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fails to properly handl2022-05-13
CVEList
CVE-2017-8758: Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fails to properly handl2017-09-13

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Server Elevation of Privilege Vulnerability2017-09-12
CVE-2017-8758 — Cross-site Scripting | cvebase