MS15-026: Vulnerabilities in Microsoft Exchange Server Could Allow Elevation of Privilege (3040856)
Medium Nessus Plugin ID 81740
SynopsisThe remote Microsoft Exchange server is affected by multiple vulnerabilities.
DescriptionThe remote Microsoft Exchange server is missing a security update. It is, therefore, affected by multiple vulnerabilities :
- Multiple cross-site scripting vulnerabilities exist due to improper sanitization of page content in Outlook Web App. An attacker can exploit these vulnerabilities by modifying properties within Outlook Web App and then convincing a user browse to the targeted Outlook Web App site, resulting in the execution of arbitrary script code in the context of the current user. (CVE-2015-1628, CVE-2015-1629, CVE-2015-1630, CVE-2015-1632)
- A spoofing vulnerability exists due to a failure to properly validate the meeting organizer's identity when accepting or modifying meeting requests. A remote attacker can exploit this issue to send forged meeting requests appearing to originate from a legitimate organizer. (CVE-2015-1631)
SolutionMicrosoft has released a set of patches for Exchange 2013.