Microsoft Exchange Server Elevation Of Privilege Vulnerability (CVE-2015-1632)
2016年11月4日
危険度: 緊急
CVE識別番号: 2015-1632,MS15-026
概要
Elevation of privilege vulnerability exists when Microsoft Exchange Server does not properly sanitize page content in Outlook Web App. An attacker could exploit this vulnerability by modifying certain properties within Outlook Web App and then convincing users to browse to the targeted Outlook Web App site. An attacker who successfully exploited this vulnerability could run script in the context of the current user.
トレンドマイクロの対策
Apply associated Trend Micro DPI Rules.
対応方法
Trend Micro Deep Security DPI Rule Number: 1000552
Trend Micro Deep Security DPI Rule Name: 1000552 - Generic Cross Site Scripting(XSS) Prevention
影響を受けるソフトウェア
- Microsoft Exchange Server