CVE-2017-11932: Input Validation
Published Dec 12, 2017
·Updated
Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka "Microsoft Exchange Spoofing Vulnerability".
Affected Software
2 affected components
Microsoft Exchange Server=2016-cumulative_update_6
Microsoft Exchange Server=2016-cumulative_update_7
Remediation
Event History
Dec 12, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-11932?
CVE-2017-11932 has been classified with a medium severity rating.
2
How do I fix CVE-2017-11932?
To fix CVE-2017-11932, you should apply the latest cumulative update for Microsoft Exchange Server.
3
Which versions of Microsoft Exchange Server are affected by CVE-2017-11932?
CVE-2017-11932 affects Microsoft Exchange Server 2016 cumulative update 5 and earlier versions.
4
Can CVE-2017-11932 lead to unauthorized access?
Yes, CVE-2017-11932 allows attackers to potentially spoof requests, which could lead to unauthorized access.
5
Is authentication impacted by CVE-2017-11932?
Yes, CVE-2017-11932 impacts the way Outlook Web Access (OWA) validates web requests, affecting authentication mechanisms.