CVE-2014-6336: Input Validation
Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the origin of e-mail messages via unspecified vectors, aka "Exchange URL Redirection Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6336?
CVE-2014-6336 has a CVSS score of 4.3, indicating it is of moderate severity.
How do I fix CVE-2014-6336?
To fix CVE-2014-6336, apply the security updates provided in Microsoft Security Bulletin MS14-075.
What impact does CVE-2014-6336 have on users?
CVE-2014-6336 allows attackers to redirect users to malicious websites, potentially leading to phishing attacks.
Which versions of Microsoft Exchange are affected by CVE-2014-6336?
CVE-2014-6336 affects Microsoft Exchange Server 2013 SP1 and Cumulative Update 6.
Is there a workaround for CVE-2014-6336?
There are no known workarounds for CVE-2014-6336, so applying patches is essential.