MS15-026: Vulnerabilities in Microsoft Exchange Server Could Allow Elevation of Privilege (3040856)

medium Nessus Plugin ID 81740
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Synopsis

The remote Microsoft Exchange server is affected by multiple vulnerabilities.

Description

The remote Microsoft Exchange server is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- Multiple cross-site scripting vulnerabilities exist due to improper sanitization of page content in Outlook Web App. An attacker can exploit these vulnerabilities by modifying properties within Outlook Web App and then convincing a user browse to the targeted Outlook Web App site, resulting in the execution of arbitrary script code in the context of the current user. (CVE-2015-1628, CVE-2015-1629, CVE-2015-1630, CVE-2015-1632)

- A spoofing vulnerability exists due to a failure to properly validate the meeting organizer's identity when accepting or modifying meeting requests. A remote attacker can exploit this issue to send forged meeting requests appearing to originate from a legitimate organizer. (CVE-2015-1631)

Solution

Microsoft has released a set of patches for Exchange 2013.

See Also

https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2015/ms15-026

Plugin Details

Severity: Medium

ID: 81740

File Name: smb_nt_ms15-026.nasl

Version: 1.9

Type: local

Agent: windows

Published: 3/10/2015

Updated: 11/22/2019

Dependencies: ms_bulletin_checks_possible.nasl

Risk Information

CVSS Score Source: CVE-2015-1631

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Temporal Vector: E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:exchange_server

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Ease: No known exploits are available

Patch Publication Date: 3/10/2015

Vulnerability Publication Date: 3/10/2015

Reference Information

CVE: CVE-2015-1628, CVE-2015-1629, CVE-2015-1630, CVE-2015-1631, CVE-2015-1632

BID: 72883, 72887, 72888, 72890, 72895

MSFT: MS15-026

MSKB: 3040856