JSON View XML View

Key Value
MTID M114448
Title (MS16-108) Microsoft Exchange Open Redirect Spoofing Information Disclosure (3185883)
Description A vulnerability in some versions of Microsoft Exchange could lead to spoofing.
Observation A vulnerability in some versions of Microsoft Exchange could lead to spoofing.

The flaw lies in the Open Redirect component. Successful exploitation could allow a remote attacker to trick the user or obtain sensitive information. The exploit requires the user to open a vulnerable website, email or document.
Recommendation The vendor has released an update to address this issue.

https://technet.microsoft.com/library/security/MS16-108

Vendor Microsoft
Attack Vector Website or e-mail with malicious content
Importance 5
Impact 4.938243750
Threat Score 5.76
Labels
Patch Tuesday
References
CVECVE-2016-3378
MSFTBulletinMS16-108
MSFTQNumber3185883
DISA IAVA2016-A-0247
MTIDM114448
CPEs
cpe:/a:microsoft:exchange_server:2016:cu2
Created At 2016-09-13 00:00:00 UTC
Updated At 2016-11-19 10:32:09 UTC

Back