Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.809313
Categoría:Windows : Microsoft Bulletins
Título:Microsoft Exchange Server Multiple Vulnerabilities (3185883)
Resumen:This host is missing an important security; update according to Microsoft Bulletin MS16-108.
Descripción:Summary:
This host is missing an important security
update according to Microsoft Bulletin MS16-108.

Vulnerability Insight:
Multiple flaws exist due to

- The way that Microsoft Exchange Server parses email messages.

- An open redirect vulnerability exists in Microsoft Exchange that
could lead to Spoofing.

- The way that Microsoft Outlook handles meeting invitation requests.

Vulnerability Impact:
Successful exploitation will allow remote
an attacker to discover confidential user information that is contained in
Microsoft Outlook applications, also attacker could trick the user and potentially
acquire sensitive information, such as the user's credentials.

Affected Software/OS:
- Microsoft Exchange Server 2013 Service Pack 1

- Microsoft Exchange Server 2013 Cumulative Update 12

- Microsoft Exchange Server 2013 Cumulative Update 13

- Microsoft Exchange Server 2016 Cumulative Update 1

- Microsoft Exchange Server 2016 Cumulative Update 2

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-0138
BugTraq ID: 92806
http://www.securityfocus.com/bid/92806
Microsoft Security Bulletin: MS16-108
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-108
http://www.securitytracker.com/id/1036778
Common Vulnerability Exposure (CVE) ID: CVE-2016-3378
BugTraq ID: 92833
http://www.securityfocus.com/bid/92833
Common Vulnerability Exposure (CVE) ID: CVE-2016-3379
BugTraq ID: 92836
http://www.securityfocus.com/bid/92836
CopyrightCopyright (C) 2016 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.