Microsoft Exchange Server Elevation of Privilege Vulnerabilities
Last Update Date:
10 Jun 2015 09:55
Release Date:
10 Jun 2015
3902
Views
RISK: Medium Risk
TYPE: Servers - Other Servers
An information disclosure vulnerability exists in Microsoft Exchange web applications when Exchange does not properly manage same-origin policy. An attacker could exploit this Server-Side Request Forgery (SSRF) vulnerability by using a specially crafted web application request.
Impact
- Elevation of Privilege
System / Technologies affected
- Microsoft Exchange Server 2013
- Microsoft Exchange Server 2013 Service Pack 1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS15-064
Vulnerability Identifier
Source
Related Link
Share with