← Back

CVE-2020-16969

nvd nist
Published: Oct 16, 2020Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD (Secondary)

Description

<p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p> <p>To exploit the vulnerability, an attacker could include specially crafted OWA messages that could be loaded, without warning or filtering, from the attacker-controlled URL. This callback vector provides an information disclosure tactic used in web beacons and other types of tracking systems.</p> <p>The security update corrects the way that Exchange handles these token validations.</p>

Affected (5)

1 product
Exchange Server
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 2013 cumulative_update_23
Version 2016 cumulative_update_17
Version 2016 cumulative_update_18
Version 2019 cumulative_update_6
Version 2019 cumulative_update_7

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.