First published: Tue Jul 11 2017(Updated: )
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnerability that could lead to spoofing, aka "Microsoft Exchange Open Redirect Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2010-sp3 | |
Microsoft Exchange Server | =2013-cumulative_update_16 | |
Microsoft Exchange Server | =2013-sp1 | |
Microsoft Exchange Server | =2016-cumulative_update_5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8621 is classified as a vulnerability that can lead to open redirection and potential spoofing attacks.
To fix CVE-2017-8621, it is recommended to apply the latest security patches provided by Microsoft for the affected versions of Exchange Server.
CVE-2017-8621 affects Microsoft Exchange Server 2010 SP3, 2013 SP3, 2013 CU16, and 2016 CU5.
CVE-2017-8621 can enable attacks that lead to open redirects and spoofing, potentially allowing unauthorized access or phishing.
Yes, exploitation of CVE-2017-8621 typically requires user interaction, such as clicking on a malicious link.