CVE-2020-16969: Microsoft Exchange Information Disclosure Vulnerability
<p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p> <p>To exploit the vulnerability, an attacker could include specially crafted OWA messages that could be loaded, without warning or filtering, from the attacker-controlled URL. This callback vector provides an information disclosure tactic used in web beacons and other types of tracking systems.</p> <p>The security update corrects the way that Exchange handles these token validations.</p>
Other sources
An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages, aka 'Microsoft Exchange Information Disclosure Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-16969?
CVE-2020-16969 is an information disclosure vulnerability in Microsoft Exchange that allows unauthorized access to certain messages.
How does CVE-2020-16969 affect Microsoft Exchange?
CVE-2020-16969 affects Microsoft Exchange versions 2013, 2016, and 2019 that have specific cumulative updates installed.
What is the severity of CVE-2020-16969?
CVE-2020-16969 has a severity of medium with a CVSS score of 6.5.
How can I fix CVE-2020-16969?
To fix CVE-2020-16969, apply the appropriate cumulative update for your version of Microsoft Exchange.
Where can I find more information about CVE-2020-16969?
You can find more information about CVE-2020-16969 on the Microsoft Security Guidance advisory page: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16969