← Back

CVE-2016-0138

nvd nist
Published: Sep 14, 2016Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Outlook application information by leveraging the Send As right, aka "Microsoft Exchange Information Disclosure Vulnerability."

Affected (7)

1 product
Exchange Server
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2007 sp3
Version 2010 sp3
Version 2013 cumulative_update_12
Version 2013 cumulative_update_13
Version 2013 sp1
Version 2016 cumulative_update_1
Version 2016 cumulative_update_2

References (6)

Source: secure@microsoft.com
Source: secure@microsoft.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.