Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.809313
Category:Windows : Microsoft Bulletins
Title:Microsoft Exchange Server Multiple Vulnerabilities (3185883)
Summary:This host is missing an important security; update according to Microsoft Bulletin MS16-108.
Description:Summary:
This host is missing an important security
update according to Microsoft Bulletin MS16-108.

Vulnerability Insight:
Multiple flaws exist due to

- The way that Microsoft Exchange Server parses email messages.

- An open redirect vulnerability exists in Microsoft Exchange that
could lead to Spoofing.

- The way that Microsoft Outlook handles meeting invitation requests.

Vulnerability Impact:
Successful exploitation will allow remote
an attacker to discover confidential user information that is contained in
Microsoft Outlook applications, also attacker could trick the user and potentially
acquire sensitive information, such as the user's credentials.

Affected Software/OS:
- Microsoft Exchange Server 2013 Service Pack 1

- Microsoft Exchange Server 2013 Cumulative Update 12

- Microsoft Exchange Server 2013 Cumulative Update 13

- Microsoft Exchange Server 2016 Cumulative Update 1

- Microsoft Exchange Server 2016 Cumulative Update 2

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-0138
BugTraq ID: 92806
http://www.securityfocus.com/bid/92806
Microsoft Security Bulletin: MS16-108
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-108
http://www.securitytracker.com/id/1036778
Common Vulnerability Exposure (CVE) ID: CVE-2016-3378
BugTraq ID: 92833
http://www.securityfocus.com/bid/92833
Common Vulnerability Exposure (CVE) ID: CVE-2016-3379
BugTraq ID: 92836
http://www.securityfocus.com/bid/92836
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.