CVE-2017-11761High

Microsoft Exchange Information Disclosure Vulnerability

Published
September 12, 2017
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An input sanitization issue exists with Microsoft Exchange that could potentially result in unintended Information Disclosure. An attacker who successfully exploited the vulnerability could identify the existence of RFC1918 addresses on the local network from a client on the Internet. An attacker could use this internal host information as part of a larger attack. To exploit the vulnerability, an attacker could include specially crafted tags in Calendar-related messages sent to an Exchange server. These specially-tagged messages could prompt the Exchange server to fetch information from internal servers. By observing telemetry from these requests, a client could discern properties of internal hosts intended to be hidden from the Internet. The update corrects the way that Exchange parses Calendar-related messages.

🎯 Affected products4

  • Microsoft Exchange Server 2013 Cumulative Update 17
  • Microsoft Exchange Server 2013 Cumulative Update 18
  • Microsoft Exchange Server 2016 Cumulative Update 6
  • Microsoft Exchange Server 2016 Cumulative Update 7

✅ Remediation

KB4045655 (Security Update)

🔗 References (5)