Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2016-0138

Опубликовано: 13 сент. 2016
Источник: msrc
EPSS Средний

Описание

Microsoft Outlook Information Disclosure Vulnerability

An information disclosure vulnerability exists in the way that Microsoft Exchange Server parses email messages. The vulnerability could allow an attacker to discover confidential user information that is contained in Microsoft Outlook applications.

To exploit the vulnerability, an attacker could use "send as" rights to send a specially crafted message to a user.

The security update addresses the vulnerability by correcting how Microsoft Exchange parses certain unstructured file formats.

Обновления

ПродуктСтатьяОбновление
Microsoft Exchange Server 2007 Service Pack 3
Microsoft Exchange Server 2010 Service Pack 3
Microsoft Exchange Server 2013 Service Pack 1
Microsoft Exchange Server 2013 Cumulative Update 12
Microsoft Exchange Server 2016 Cumulative Update 1
Microsoft Exchange Server 2013 Cumulative Update 13
Microsoft Exchange Server 2016 Cumulative Update 2

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

Older Software Release

N/A

DOS

N/A

EPSS

Процентиль: 94%
0.16066
Средний

Связанные уязвимости

CVSS3: 4.3
nvd
почти 9 лет назад

Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Outlook application information by leveraging the Send As right, aka "Microsoft Exchange Information Disclosure Vulnerability."

CVSS3: 4.3
github
около 3 лет назад

Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Outlook application information by leveraging the Send As right, aka "Microsoft Exchange Information Disclosure Vulnerability."

fstec
почти 9 лет назад

Уязвимость почтового сервера Microsoft Exchange Server, позволяющая нарушителю получить доступ к защищаемой информации приложения Outlook

EPSS

Процентиль: 94%
0.16066
Средний