Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2016-3379

Опубликовано: 13 сент. 2016
Источник: msrc
EPSS Низкий

Описание

Microsoft Exchange Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way that Microsoft Outlook handles meeting invitation requests.

To exploit the vulnerability, an attacker could send a specially crafted Outlook meeting invitation request with malicious cross-site scripting (XSS) capability to a user.

The update addresses the vulnerability by correcting how Outlook handles meeting invitation requests.

Обновления

ПродуктСтатьяОбновление
Microsoft Exchange Server 2016 Cumulative Update 1
Microsoft Exchange Server 2016 Cumulative Update 2

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

N/A

DOS

N/A

EPSS

Процентиль: 91%
0.0716
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
почти 9 лет назад

Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attackers to inject arbitrary web script or HTML via a meeting-invitation request, aka "Microsoft Exchange Elevation of Privilege Vulnerability."

CVSS3: 6.1
github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attackers to inject arbitrary web script or HTML via a meeting-invitation request, aka "Microsoft Exchange Elevation of Privilege Vulnerability."

EPSS

Процентиль: 91%
0.0716
Низкий