First published: Tue Apr 09 2019(Updated: )
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0817.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2013-cumulative_update_22 | |
Microsoft Exchange Server | =2016-cumulative_update_11 | |
Microsoft Exchange Server | =2016-cumulative_update_12 | |
Microsoft Exchange Server | =2019 | |
Microsoft Exchange Server | =2019-cumulative_update_1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0858 has a severity rating of important, indicating it poses a moderate risk to systems.
To fix CVE-2019-0858, apply the latest cumulative update for your version of Microsoft Exchange Server.
CVE-2019-0858 affects Microsoft Exchange Server 2013, 2016, and 2019 on specific cumulative updates.
CVE-2019-0858 is caused by improper handling of web requests in Outlook Web Access (OWA) on Microsoft Exchange Server.
CVE-2019-0858 has been noted as a specific high-impact vulnerability that can potentially lead to spoofing attacks.