QID 50134
Date Published: 2023-11-16
QID 50134: Microsoft Exchange Server Authenticated Server Side Request Forgery (SSRF) Vulnerability (Zero Day)
Microsoft Exchange server is vulnerable to an authenticated SSRF vulnerability. The specific flaw exists within the 'CreateAttachmentFromUri' method. The issue results from the lack of proper validation of a URI prior to accessing resources. An attacker can leverage this vulnerability to access internal websites or servers otherwise not accessible.
Affected Versions:
The vulnerability affects all versions of Microsoft Exchange Server.
QID Detection Logic (Authenticated):
The QID checks for vulnerable version of Microsoft Exchange Server by checking the file version of Exsetup.exe.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of MS Exchange Server by sending a GET request to /owa endpoint.
Successful exploitation of the vulnerability may allow a remote attacker to disclose sensitive information on affected installations of Microsoft Exchange. Authentication is required to exploit this vulnerability.
CVEs related to QID 50134
| Advisory ID | Software | Component | Link |
|---|