SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-11761

Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability"

MEDIUM 5.3EPSS 6.56%

Does this matter?

Lower severity and a low EPSS score (6.56%). Track it; it rarely justifies an emergency change on its own.

Description

Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability"

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
6.56% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
microsoft/exchange server
Source
secure@microsoft.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.