First published: Wed Sep 11 2019(Updated: )
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2016-cumulative_update_12 | |
Microsoft Exchange Server | =2016-cumulative_update_13 | |
Microsoft Exchange Server | =2019-cumulative_update_1 | |
Microsoft Exchange Server | =2019-cumulative_update_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1266 is rated as important as it can lead to spoofing attacks in Microsoft Exchange Server.
To fix CVE-2019-1266, ensure that your Microsoft Exchange Server is updated with the latest cumulative updates.
CVE-2019-1266 affects Microsoft Exchange Server 2016 Cumulative Update 12 and 13, and 2019 Cumulative Update 1 and 2.
CVE-2019-1266 can allow an attacker to spoof sent messages, potentially misleading users.
Currently, the only recommended solution for CVE-2019-1266 is applying the security updates provided by Microsoft.