Описание
Microsoft Exchange Server Security Feature Bypass Vulnerability
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
FAQ
What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An authenticated attacker who successfully exploited this vulnerability could bypass a role-based restriction that is intended to control which users are allowed to install mail add-ins. By bypassing this control, a user could install an add-in that requests elevated mailbox permissions that an administrator's policy was meant to prevent.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Microsoft Exchange Server 2016 Cumulative Update 23 | - | |
| Microsoft Exchange Server 2019 Cumulative Update 14 | - | |
| Microsoft Exchange Server 2019 Cumulative Update 15 | - | |
| Microsoft Exchange Server Subscription Edition RTM |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
EPSS
6.5 Medium
CVSS3