MS15-026: Vulnerabilities in Microsoft Exchange Server Could Allow Elevation of Privilege (3040856)

Medium Nessus Plugin ID 81740


The remote Microsoft Exchange server is affected by multiple vulnerabilities.


The remote Microsoft Exchange server is missing a security update. It is, therefore, affected by multiple vulnerabilities :

- Multiple cross-site scripting vulnerabilities exist due to improper sanitization of page content in Outlook Web App. An attacker can exploit these vulnerabilities by modifying properties within Outlook Web App and then convincing a user browse to the targeted Outlook Web App site, resulting in the execution of arbitrary script code in the context of the current user. (CVE-2015-1628, CVE-2015-1629, CVE-2015-1630, CVE-2015-1632)

- A spoofing vulnerability exists due to a failure to properly validate the meeting organizer's identity when accepting or modifying meeting requests. A remote attacker can exploit this issue to send forged meeting requests appearing to originate from a legitimate organizer. (CVE-2015-1631)


Microsoft has released a set of patches for Exchange 2013.

See Also

Plugin Details

Severity: Medium

ID: 81740

File Name: smb_nt_ms15-026.nasl

Version: $Revision: 1.5 $

Type: local

Agent: windows

Published: 2015/03/10

Modified: 2017/07/24

Dependencies: 57033

Risk Information

Risk Factor: Medium


Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:exchange_server

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2015/03/10

Vulnerability Publication Date: 2015/03/10

Reference Information

CVE: CVE-2015-1628, CVE-2015-1629, CVE-2015-1630, CVE-2015-1631, CVE-2015-1632

BID: 72883, 72888, 72887, 72890, 72895

OSVDB: 119377, 119378, 119379, 119380, 119381

MSFT: MS15-026

MSKB: 3040856

IAVA: 2015-A-0049