VulnerabilityModified
CVE-2017-8758
Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability."
MEDIUM 6.1EPSS 3.38%
Does this matter?
Lower severity and a low EPSS score (3.38%). Track it; it rarely justifies an emergency change on its own.
Description
Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability."
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 3.38% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- microsoft/exchange server
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/100723Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039320Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8758Patch, Vendor Advisory
- http://www.securityfocus.com/bid/100723Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039320Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8758Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.