CVE-2016-0028: Infoleak
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, aka "Microsoft Exchange Information Disclosure Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0028?
CVE-2016-0028 is classified as a medium severity vulnerability.
How can I fix CVE-2016-0028?
To mitigate CVE-2016-0028, apply the recommended security updates provided by Microsoft for affected Exchange Server versions.
Which software versions are affected by CVE-2016-0028?
CVE-2016-0028 affects Microsoft Exchange Server 2013 SP1, Cumulative Update 11, Cumulative Update 12 and Microsoft Exchange Server 2016, including Cumulative Update 1.
What type of attack is associated with CVE-2016-0028?
CVE-2016-0028 allows remote attackers to track users through crafted HTML email messages due to improper loading restrictions of IMG elements.
Is CVE-2016-0028 still a risk for users?
Users running unpatched versions of affected Microsoft Exchange products remain at risk from CVE-2016-0028.