CVE-2017-8559: XSS
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". This CVE ID is unique from CVE-2017-8560.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8559?
CVE-2017-8559 has been rated as important by Microsoft due to its potential for elevation of privilege.
How do I fix CVE-2017-8559?
To mitigate CVE-2017-8559, update Microsoft Exchange Server to the latest service pack or cumulative update provided by Microsoft.
What types of software are affected by CVE-2017-8559?
CVE-2017-8559 affects Microsoft Exchange Server 2010 SP3, 2013 SP3, 2013 CU16, and 2016 CU5.
What is the nature of the vulnerability in CVE-2017-8559?
CVE-2017-8559 is an elevation of privilege vulnerability involving improper handling of web requests by Exchange Outlook Web Access.
Is there any workaround for CVE-2017-8559?
There are no known workarounds for CVE-2017-8559; applying the security updates is the recommended course of action.