First published: Tue Sep 07 2010(Updated: )
Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Outlook | =2007 | |
Microsoft Outlook | =2007-sp1 | |
Microsoft Outlook | =2007-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3213 has a medium severity rating due to its potential to allow unauthorized access to user accounts.
To mitigate CVE-2010-3213, it is recommended to apply the latest security updates provided by Microsoft for Outlook Web Access.
CVE-2010-3213 affects Microsoft Outlook Web Access 2007 SP1, 2007, and 2007 SP2.
CVE-2010-3213 represents a cross-site request forgery (CSRF) attack, allowing attackers to execute actions on behalf of authenticated users.
Yes, CVE-2010-3213 allows remote attackers to hijack the authentication of e-mail users, compromising user accounts.