(MS15-026) Vulnerabilities in Microsoft Exchange Server Could Allow Elevation of Privilege (3040856)
Publish Date: 02 de kwietnia de 2015
Severity: : High
CVE Identifier: CVE-2015-1628,CVE-2015-1629,CVE-2015-1630,CVE-2015-1631,CVE-2015-1632
Advisory Date: 02 de kwietnia de 2015
DESCRIPTION
This security update resolves vulnerabilities in Microsoft Exchange Server. The most severe of the vulnerabilities could allow elevation of privilege if a user clicks a specially crafted URL that takes them to a targeted Outlook Web App site. An attacker would have no way to force users to visit a specially crafted website. Instead, an attacker would have to convince them to visit the website, typically by getting them to click a link in an instant messenger or email message that takes them to the attacker's website, and then convince them to click the specially crafted URL.
SOLUTION
AFFECTED SOFTWARE AND VERSION:
- Microsoft Exchange Server 2013 Service Pack 1
- Microsoft Exchange Server 2013 Cumulative Update 7