CVE-2017-8758

MEDIUM

Microsoft Exchange Server 2016 - Cross-Site Scripting in Outlook Web Access

Title source: llm
STIX 2.1

Description

Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability."

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100723
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039320

Scores

CVSS v3 6.1
EPSS 0.0092
EPSS Percentile 76.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
microsoft/exchange_server 2016
Microsoft Corporation/Microsoft Exchange Server 2016 Microsoft Exchange Server 2016 Cumulative Update 6
Published Sep 13, 2017
Tracked Since Feb 18, 2026