Microsoft Exchange User Account Enumeration Information Disclosure Vulnerability
BID:69026
Info
Microsoft Exchange User Account Enumeration Information Disclosure Vulnerability
| Bugtraq ID: | 69026 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2014 12:00AM |
| Updated: | Aug 01 2014 12:00AM |
| Credit: | Nate Power |
| Vulnerable: |
Microsoft Forefront Threat Management Gateway 2010 0 Microsoft Exchange Server 2013 0 Microsoft Exchange Server 2007 0 Microsoft Exchange Server 2010 |
| Not Vulnerable: | |
Discussion
Microsoft Exchange User Account Enumeration Information Disclosure Vulnerability
Microsoft Exchange is prone to an information-disclosure vulnerability.
An attacker can leverage this issue to enumerate user accounts of the system. Information obtained may aid in further attacks.
Microsoft Exchange is prone to an information-disclosure vulnerability.
An attacker can leverage this issue to enumerate user accounts of the system. Information obtained may aid in further attacks.
Exploit / POC
Microsoft Exchange User Account Enumeration Information Disclosure Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
The following exploit is available:
Attackers can use standard, readily available tools to exploit this issue.
The following exploit is available: