CVE-2016-3378: Input Validation
Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "Microsoft Exchange Open Redirect Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3378?
CVE-2016-3378 is considered to have a moderate severity level due to its potential for exploitation in phishing attacks.
How do I fix CVE-2016-3378?
To fix CVE-2016-3378, apply the latest security updates provided by Microsoft for the affected versions of Exchange Server.
What versions of Microsoft Exchange Server are affected by CVE-2016-3378?
CVE-2016-3378 affects Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2.
Can CVE-2016-3378 lead to remote attacks?
Yes, CVE-2016-3378 allows remote attackers to redirect users to arbitrary websites, facilitating phishing attacks.
What type of vulnerability is CVE-2016-3378?
CVE-2016-3378 is classified as an open redirect vulnerability.