First published: Wed Jun 10 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2013-cumulative_update_8 | |
Microsoft Exchange Server | =2013-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1771 has a severity rating of critical because it allows remote attackers to hijack user authentication.
To fix CVE-2015-1771, apply the security updates available from Microsoft for Exchange Server 2013 SP1 and Cumulative Update 8.
Due to CVE-2015-1771, attackers can perform cross-site request forgery attacks, leading to unauthorized actions on behalf of users.
CVE-2015-1771 affects users of Microsoft Exchange Server 2013 SP1 and Cumulative Update 8.
Check systems running Microsoft Exchange Server 2013 SP1 or Cumulative Update 8 to identify potential vulnerabilities related to CVE-2015-1771.