CVE-2015-1771: CSRF
Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1771?
CVE-2015-1771 has a severity rating of critical because it allows remote attackers to hijack user authentication.
How do I fix CVE-2015-1771?
To fix CVE-2015-1771, apply the security updates available from Microsoft for Exchange Server 2013 SP1 and Cumulative Update 8.
What types of attacks are possible due to CVE-2015-1771?
Due to CVE-2015-1771, attackers can perform cross-site request forgery attacks, leading to unauthorized actions on behalf of users.
Who is affected by CVE-2015-1771?
CVE-2015-1771 affects users of Microsoft Exchange Server 2013 SP1 and Cumulative Update 8.
What systems should I check for CVE-2015-1771 vulnerability?
Check systems running Microsoft Exchange Server 2013 SP1 or Cumulative Update 8 to identify potential vulnerabilities related to CVE-2015-1771.