Microsoft Exchange Server CVE-2017-8621 Open Redirection Vulnerability
by CIRT Team
Description: An open redirect vulnerability exists in Microsoft Exchange that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL, and convince the user to click the link. When an authenticated Exchange user clicks the link, the authenticated user’s browser session could be redirected to a malicious site that is designed to impersonate a legitimate website. By doing so, the attacker could trick the user and potentially acquire sensitive information, such as the user’s credentials.
Impact: An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Mitigation: Updates are available. Please check specific vendor advisory for more information.
Reference URL’s:
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8621
- http://www.securityfocus.com/bid/99533/info
Recommended Posts
Active Exploitation of Critical F5 BIG – IP Vulnerability (CVE–2023-46747) Uncovered in Bangladesh
06 Nov 2024 - Security Advisories & Alerts