CVE-2017-8560
CVE-2017-8560
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 3.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
11 Jul 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". This CVE ID is unique from CVE-2017-8559.
Affected products
Microsoft Corporation · Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5.Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →