Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, aka "Microsoft Exchange Information Disclosure Vulnerability."
2016-06-16T01:59:03.167
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 5.5 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | microsoft | exchange_server | 2013 | No |
| Application | microsoft | exchange_server | 2013 | No |
| Application | microsoft | exchange_server | 2013 | No |
| Application | microsoft | exchange_server | 2016 | No |
| Application | microsoft | exchange_server | 2016 | No |
| Application | microsoft | outlook_web_access | * | Yes |