CVE-2017-8560: XSS
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". This CVE ID is unique from CVE-2017-8559.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8560?
The severity of CVE-2017-8560 is considered to be high due to its potential for elevation of privilege.
How do I fix CVE-2017-8560?
To fix CVE-2017-8560, apply the latest security updates provided by Microsoft for the affected versions of Exchange Server.
What versions of Microsoft Exchange Server are affected by CVE-2017-8560?
CVE-2017-8560 affects Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5.
What type of vulnerability is CVE-2017-8560?
CVE-2017-8560 is classified as a Cross-Site Scripting (XSS) vulnerability that can lead to elevation of privilege.
Can CVE-2017-8560 be exploited remotely?
Yes, CVE-2017-8560 can be exploited remotely through affected Outlook Web Access (OWA) web requests.