CVE-2016-0032
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, 2013 Cumulative Update 11, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL,…
Does this matter?
Lower severity and a low EPSS score (7.58%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, 2013 Cumulative Update 11, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability."
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 7.58% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- microsoft/exchange server
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/79884Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034647Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-010Patch, Vendor Advisory
- http://www.securityfocus.com/bid/79884Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034647Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-010Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.