CVE-2019-1266

Severity
6.1MEDIUM
EPSS
0.4%
top 40.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateMay 24

Description

A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

NVDmicrosoft/exchange_server2016, 2019+1
CVEListV5microsoft/microsoft_exchange_server_2016Cumulative Update 12, Cumulative Update 13+1
CVEListV5microsoft/microsoft_exchange_server_2019Cumulative Update 1, Cumulative Update 2+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vjmv-ghrr-vr6w: A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange2022-05-24
GHSA
Jenkins Script Security Plugin sandbox bypass vulnerability2022-05-13
CVEList
CVE-2019-1266: A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange2019-09-11

💥Exploits & PoCs

1
Exploit-DB
Jenkins Plugin Script Security 1.49/Declarative 1.3.4/Groovy 2.60 - Remote Code Execution2019-02-25

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Spoofing Vulnerability2019-09-10

💬Community

1
Bugzilla
CVE-2019-1003005 jenkins-plugin-script-security: Sandbox Bypass in Script Security Plugin (SECURITY-1292)2019-01-29
CVE-2019-1266 (MEDIUM CVSS 6.1) | A spoofing vulnerability exists in | cvebase.io