CVE-2020-16969
Published: Oct 16, 2020
Modified: Aug 4, 2024
CVSS v3.1
7.1
Description
<p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p> <p>To exploit the vulnerability, an attacker could include specially crafted OWA messages that could be loaded, without warning or filtering, from the attacker-controlled URL. This callback vector provides an information disclosure tactic used in web beacons and other types of tracking systems.</p> <p>The security update corrects the way that Exchange handles these token validations.</p>
| Vendor | Product | Versions |
|---|---|---|
Microsoft | Microsoft Exchange Server 2019 Cumulative Update 6 | affected 15.02.0 - < publication |
Microsoft | Microsoft Exchange Server 2016 Cumulative Update 17 | affected 15.01.0 - < publication |
Microsoft | Microsoft Exchange Server 2019 Cumulative Update 7 | affected 15.02.0 - < publication |
Microsoft | Microsoft Exchange Server 2016 Cumulative Update 18 | affected 15.01.0 - < publication |
Microsoft | Microsoft Exchange Server 2013 Cumulative Update 23 | affected 15.00.0 - < publication |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now