CVE-2017-11761
Summary
| CVE | CVE-2017-11761 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-13 01:29:00 UTC |
| Updated | 2017-09-21 16:08:00 UTC |
| Description | Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability" |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Exchange Server | 2013 | cumulative_update_16 | All | All |
| Application | Microsoft | Exchange Server | 2013 | cumulative_update_17 | All | All |
| Application | Microsoft | Exchange Server | 2013 | sp1 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_5 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_6 | All | All |
| Application | Microsoft | Exchange Server | 2013 | cumulative_update_16 | All | All |
| Application | Microsoft | Exchange Server | 2013 | cumulative_update_17 | All | All |
| Application | Microsoft | Exchange Server | 2013 | sp1 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_5 | All | All |
| Application | Microsoft | Exchange Server | 2016 | cumulative_update_6 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Exchange Server CVE-2017-11761 Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Microsoft Exchange Server Input Validation Bugs Let Remote Users Obtain Potentially Sensitive Information and Condcut Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| {{windowTitle}} | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.