Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
| Vendor | Product | Versions |
|---|---|---|
| microsoft | exchange_server | 15.01.0.0, 15.02.0.0, 15.02.0.0, 15.02.0.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| microsoft | microsoft exchange server 2019 cumulative update | mitre_affected | 90% |
| microsoft | microsoft exchange server subscription edition rtm | mitre_affected | 90% |
| microsoft | exchange | cert_advisory | 90% |
| microsoft | exchange_server_subscription_edition | cve_cpe | 95% |
Updated description with technical details on exploitation and added patch release date.
Updated affected versions to include Exchange Server 2016, 2019, and Subscription Edition, and added relevant tags.
Updated patch availability to null and added new tags related to security updates and arbitrary code execution.
Updated affected versions to include specific cumulative updates and confirmed the patch URL.
Updated description with new technical details, specified affected versions, and noted that a patch is still in progress.
Updated severity to CRITICAL, added affected versions, and specified future patch availability.
Updated severity to CRITICAL and added new affected versions for on-premises products.
Updated description with more technical detail, added affected versions for Exchange Server Subscription Edition, 2016, and 2019, and noted that a permanent patch is not yet available.
Updated affected versions to include all existing versions of Exchange Server 2016, 2019, and Subscription Edition, and noted that no patch is currently available.
Added new affected versions for Microsoft Exchange Server.
Updated severity to CRITICAL, added affected version Subscription Edition RTM, and noted that a permanent fix is still in the works.
Updated affected versions to include Exchange Server 2016, 2019, and Subscription Edition, and added patch information along with a new tag for EEMS.
Initial creation