
16/6/2016

5/8/2024
CVE-2016-0028: Infoleak
First published: Thu Jun 16 2016(Updated: )
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, aka "Microsoft Exchange Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|
Microsoft Exchange Server | =2013-cumulative_update_11 | |
Microsoft Exchange Server | =2013-cumulative_update_12 | |
Microsoft Exchange Server | =2013-sp1 | |
Microsoft Exchange Server | =2016 | |
Microsoft Exchange Server | =2016-cumulative_update_1 | |
Microsoft Outlook | | |
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is the severity of CVE-2016-0028?
CVE-2016-0028 is classified as a medium severity vulnerability.
How can I fix CVE-2016-0028?
To mitigate CVE-2016-0028, apply the recommended security updates provided by Microsoft for affected Exchange Server versions.
Which software versions are affected by CVE-2016-0028?
CVE-2016-0028 affects Microsoft Exchange Server 2013 SP1, Cumulative Update 11, Cumulative Update 12 and Microsoft Exchange Server 2016, including Cumulative Update 1.
What type of attack is associated with CVE-2016-0028?
CVE-2016-0028 allows remote attackers to track users through crafted HTML email messages due to improper loading restrictions of IMG elements.
Is CVE-2016-0028 still a risk for users?
Users running unpatched versions of affected Microsoft Exchange products remain at risk from CVE-2016-0028.
- agent/references
- agent/type
- agent/softwarecombine
- agent/weakness
- agent/severity
- agent/author
- agent/description
- collector/mitre-cve
- source/MITRE
- agent/last-modified-date
- agent/first-publish-date
- agent/event
- agent/source
- agent/tags
- collector/nvd-index
- agent/software-canonical-lookup-request
- vendor/microsoft
- canonical/microsoft exchange server
- version/microsoft exchange server/2013-cumulative_update_11
- version/microsoft exchange server/2013-cumulative_update_12
- version/microsoft exchange server/2013-sp1
- version/microsoft exchange server/2016
- version/microsoft exchange server/2016-cumulative_update_1
- canonical/microsoft outlook
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203