New Search

Exchange Cross-Site Request Forgery vulnerability - CVE-2015-1771 (MS15-064)

oval:org.mitre.oval:def:29115

Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users aka "Exchange Cross-Site Request Forgery Vulnerability."

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2012 R2
Class:
vulnerability
Reference(s):
  • CVE-2015-1771
Product(s):
  • Microsoft Exchange Server 2013